Skip to content
Noroxi

Mozilla records

3,824 published records for vendor mozilla.

All records

3,824 records
  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023

  • Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    mozilla · firefoxOct 27, 2010

  • Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxe

    CriticalCVSS 10.0KEVWeaponizedEPSS 56%

    mozilla · firefoxJul 23, 2019

  • A use-after-free vulnerability in SVG Animation has been discovered.

    HighCVSS 7.5KEVWeaponizedEPSS 87%

    debian · debian linuxJun 11, 2018

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxJun 25, 2013

  • The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxAug 7, 2015

  • Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    google · chromeSep 28, 2023

  • CVE-2019-17026
    79This week

    Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.

    HighCVSS 8.8KEVWeaponizedEPSS 46%

    mozilla · firefoxMar 2, 2020

  • CVE-2019-11707
    76This week

    A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.

    HighCVSS 8.8KEVWeaponizedEPSS 38%

    mozilla · firefoxJul 23, 2019

  • CVE-2024-9680
    76This week

    An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.

    CriticalCVSS 9.8KEVWeaponizedEPSS 23%

    mozilla · firefoxOct 9, 2024

  • CVE-2022-26485
    69This week

    Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.

    HighCVSS 8.8KEVWeaponizedEPSS 14%

    mozilla · firefoxDec 22, 2022

  • CVE-2022-26486
    69This week

    An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.

    CriticalCVSS 9.6KEVWeaponizedEPSS 2%

    mozilla · firefoxDec 22, 2022

  • CVE-2009-3555
    65This week

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    CriticalCVSS 9.8Proof of conceptEPSS 87%

    apache · http serverNov 9, 2009

  • CVE-2014-1511
    64This week

    Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa

    CriticalCVSS 9.8WeaponizedEPSS 84%

    mozilla · firefoxMar 19, 2014

  • CVE-2014-1510
    64This week

    The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25

    CriticalCVSS 9.8WeaponizedEPSS 82%

    mozilla · firefoxMar 19, 2014

  • CVE-2020-6820
    64This week

    Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.

    HighCVSS 8.1KEVWeaponizedEPSS 7%

    mozilla · firefoxApr 24, 2020

  • CVE-2011-2371
    63This week

    Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM

    CriticalCVSS 10.0WeaponizedEPSS 76%

    mozilla · seamonkeyJun 30, 2011

  • CVE-2020-6819
    63This week

    Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.

    HighCVSS 8.1KEVWeaponizedEPSS 3%

    mozilla · firefoxApr 24, 2020

  • CVE-2011-0065
    62This week

    Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers

    CriticalCVSS 10.0WeaponizedEPSS 74%

    mozilla · firefoxMay 7, 2011

  • CVE-2011-0073
    61This week

    Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which

    CriticalCVSS 10.0WeaponizedEPSS 70%

    mozilla · firefoxMay 7, 2011

  • Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before

    CriticalCVSS 9.3WeaponizedEPSS 73%

    mozilla · firefoxJan 13, 2013

  • Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper

    MediumCVSS 6.5KEVWeaponizedEPSS 7%

    mozilla · firefoxMay 16, 2013

  • A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.

    HighCVSS 8.8Proof of conceptEPSS 71%

    mozilla · firefoxMay 14, 2024

  • The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Th

    CriticalCVSS 9.3WeaponizedEPSS 61%

    mozilla · firefoxJan 13, 2013

  • Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti

    HighCVSS 7.5WeaponizedEPSS 79%

    mozilla · firefoxJul 27, 2006