mozilla
3,565 tracked vulnerabilities.
CVE-2017-7771
HIGH
Firefox < 54.0 - Out-of-bounds Read in Graphite2 Library
Apr 15, 2019
CVSS 8.1
EPSS 0.01
CVE-2017-7772
HIGH
Firefox < 54.0 - Heap-based Buffer Overflow in Graphite2 lz4::decompress
Apr 12, 2019
CVSS 8.8
EPSS 0.01
CVE-2017-7848
MEDIUM
Thunderbird < 52.5.2 - Email Header Injection via RSS Feed
Jun 11, 2018
CVSS 5.3
EPSS 0.02
CVE-2017-7847
MEDIUM
Debian Linux < 52.5.2 - Information Disclosure
Jun 11, 2018
CVSS 4.3
EPSS 0.01
CVE-2017-7846
HIGH
Redhat Enterprise Linux Desktop < 52.5.2 - Injection
Jun 11, 2018
CVSS 8.8
EPSS 0.01
CVE-2017-7845
HIGH
Firefox < 52.5.2 - Buffer Overflow in ANGLE Graphics Library
Jun 11, 2018
CVSS 8.8
EPSS 0.01
CVE-2017-7844
MEDIUM
Firefox < 57.0.1 - Unauthorized History Query via SVG Image and Anchor Link Coloring
Jun 11, 2018
CVSS 6.5
EPSS 0.01
CVE-2017-7843
HIGH
Redhat Enterprise Linux Server < 57.0.1 - Information Disclosure
Jun 11, 2018
CVSS 7.5
EPSS 0.01
CVE-2017-7842
MEDIUM
Firefox < 57 - Referrer Policy Bypass via Link Element Request
Jun 11, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-7840
MEDIUM
Firefox < 57 - Stored Cross-Site Scripting via Bookmark Tag Export
Jun 11, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-7839
MEDIUM
Firefox < 57 - Cross-Site Scripting via JavaScript URL Address Bar Bypass
Jun 11, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-7838
MEDIUM
Firefox < 57 - Limited Spoofing via Punycode Subdomain Display
Jun 11, 2018
CVSS 5.3
EPSS 0.01
CVE-2017-7837
MEDIUM
Firefox < 57 - Cookie Injection via SVG Meta Tags in IMG Elements
Jun 11, 2018
CVSS 5.3
EPSS 0.01
CVE-2017-7836
HIGH
Firefox < 57 - Privilege Escalation via Pingsender Dynamic Library Loading
Jun 11, 2018
CVSS 7.8
EPSS 0.00
CVE-2017-7835
HIGH
Firefox < 57 - Mixed Content Blocking Bypass via HTTPS-to-HTTP Redirect
Jun 11, 2018
CVSS 7.3
EPSS 0.01
CVE-2017-7834
MEDIUM
Firefox < 57 - Cross-Site Scripting via Data URL CSP Bypass
Jun 11, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-7833
MEDIUM
Firefox < 57 - Domain Spoofing via Arabic and Indic Vowel Marker Characters
Jun 11, 2018
CVSS 5.3
EPSS 0.01
CVE-2017-7832
MEDIUM
Firefox < 57 - Domain Spoofing via Unicode Dotless 'i' Character
Jun 11, 2018
CVSS 5.3
EPSS 0.01
CVE-2017-7831
MEDIUM
Firefox < 57 - Exposure of Sensitive Information via Deprecated _exposedProps_ Mechanism
Jun 11, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-7830
MEDIUM
Firefox < 57, Firefox ESR < 52.5, Thunderbird < 52.5 - Info Disclosure
Jun 11, 2018
CVSS 6.5
EPSS 0.01
CVE-2017-7829
MEDIUM
Thunderbird < 52.5.2 - Email Sender Address Spoofing via Null Character Injection
Jun 11, 2018
CVSS 5.3
EPSS 0.02
CVE-2017-7828
CRITICAL
Debian Linux < 57.0 - Use After Free
Jun 11, 2018
CVSS 9.8
EPSS 0.29
CVE-2017-7827
CRITICAL
Firefox < 57 - Memory Corruption and Remote Code Execution
Jun 11, 2018
CVSS 9.8
EPSS 0.03
CVE-2017-7826
CRITICAL
Debian Linux < 57.0 - Memory Corruption
Jun 11, 2018
CVSS 9.8
EPSS 0.02
CVE-2017-7825
MEDIUM
Debian Linux < 52.4.0 - Improper Input Validation
Jun 11, 2018
CVSS 5.3
EPSS 0.02
Products
firefox 3,130
thunderbird 1,729
seamonkey 704
firefox_esr 488
Firefox 387
Thunderbird 359
thunderbird_esr 228
bugzilla 145
mozilla 108
network_security_services 50
Firefox ESR 44
mozilla_suite 27
firefox_focus 20
firefox_mobile 20
Firefox for iOS 19
focus 15
firefox_os 14
nss 6
Focus for iOS 5
bleach 5
bonsai 4
camino 4
vpn 4
convict 3
netscape_portable_runtime 3
geckodriver 2
mozjpeg 2
nunjucks 2
pollbot 2
webthings_gateway 2
Quick Filters