Vulnerabilities > Mozilla > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-26 CVE-2018-18513 NULL Pointer Dereference vulnerability in Mozilla Thunderbird
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature.
network
low complexity
mozilla CWE-476
7.5
2019-04-26 CVE-2018-5179 Missing Release of Resource after Effective Lifetime vulnerability in Mozilla Firefox
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users.
network
low complexity
mozilla CWE-772
7.5
2019-04-15 CVE-2017-7777 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
network
low complexity
mozilla sil CWE-119
8.8
2019-04-15 CVE-2017-7776 Out-of-bounds Read vulnerability in multiple products
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
network
low complexity
mozilla sil CWE-125
8.1
2019-04-15 CVE-2017-7773 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
network
low complexity
mozilla sil CWE-119
8.8
2019-04-15 CVE-2017-7771 Out-of-bounds Read vulnerability in multiple products
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
network
low complexity
mozilla sil CWE-125
8.1
2019-04-12 CVE-2017-7772 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
network
low complexity
mozilla sil CWE-119
8.8
2019-02-28 CVE-2018-18496 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory.
network
low complexity
mozilla CWE-1021
8.8
2019-02-28 CVE-2018-12406 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 63.
network
low complexity
mozilla canonical CWE-119
8.8
2019-02-28 CVE-2018-12401 Improper Input Validation vulnerability in multiple products
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string.
network
low complexity
mozilla canonical CWE-20
7.5