CVEs (1,729)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)...Show more |
The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to...Show more |
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possi...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Jul 23, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption...Show more |
1Mozilla 4Firefox Firefox EsrNetwork Security Services+1 moreMay 6, 2026 Jul 23, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attacke...Show more |
Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct click...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cau...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote att...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execu...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects,...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (o...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of serv...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which a...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to ex...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors. |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privile...Show more |