CVEs (1,729)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption...Show more |
Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows re...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, whic...Show more |
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors invo...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Feb 25, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption...Show more |
2Mozilla Opensuse5Evergreen FirefoxFirefox Esr+2 moreMay 6, 2026 Feb 25, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local us...Show more |
3Canonical MozillaRedhat5Enterprise Linux FirefoxFirefox Esr+2 moreMay 6, 2026 Feb 25, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execu...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Feb 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uni...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Feb 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code. |
1Mozilla 4Firefox Firefox EsrSeamonkey+1 moreMay 6, 2026 Jan 14, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Requir...Show more |
1Mozilla 4Firefox Firefox EsrSeamonkey+1 moreMay 6, 2026 Jan 14, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypa...Show more |
1Mozilla 4Firefox Firefox EsrSeamonkey+1 moreMay 6, 2026 Jan 14, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of serv...Show more |
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local user...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLay...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execut...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to exe...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of serv...Show more |
content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to...Show more |
The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not properly recognize Stop Sharing actions for videos in...Show more |