Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
olli pettay vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2016-2829
Mozilla Firefox prior to 47.0 allows remote malicious users to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 15.10
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
Mozilla Firefox
Opensuse Opensuse 13.2
Opensuse Opensuse 13.1
Opensuse Leap 42.1
6.1
CVSSv3
CVE-2016-2833
Mozilla Firefox prior to 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks via a crafted applet.
Opensuse Leap 42.1
Opensuse Opensuse 13.2
Opensuse Opensuse 13.1
Mozilla Firefox
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 15.10
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
NA
CVE-2011-2369
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x up to and including 4.0.1 allows remote malicious users to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.
Mozilla Firefox 4.0
Mozilla Firefox 4.0.1
NA
CVE-2013-0772
The RasterImage::DrawFrameTo function in Mozilla Firefox prior to 19.0, Thunderbird prior to 17.0.3, and SeaMonkey prior to 2.16 allows remote malicious users to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application cras...
Mozilla Firefox
Mozilla Seamonkey
Opensuse Opensuse 11.4
Opensuse Opensuse 12.1
Opensuse Opensuse 12.2
Redhat Enterprise Linux Aus 5.9
Redhat Enterprise Linux Desktop 5.0
Redhat Enterprise Linux Desktop 6.0
Redhat Enterprise Linux Eus 5.9
Redhat Enterprise Linux Eus 6.3
Redhat Enterprise Linux Server 5.0
Redhat Enterprise Linux Server 6.0
Redhat Enterprise Linux Workstation 5.0
Redhat Enterprise Linux Workstation 6.0
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 11.10
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 12.10
NA
CVE-2015-0805
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox prior to 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote malicious users to execute arbitrary code or ca...
Opensuse Opensuse 13.2
Opensuse Opensuse 13.1
Mozilla Firefox
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 14.10
Canonical Ubuntu Linux 12.04
NA
CVE-2015-4514
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox prior to 42.0 allow remote malicious users to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Mozilla Firefox
Mozilla Firefox Esr 38.0.5
Mozilla Firefox Esr 38.1.0
Mozilla Firefox Esr 38.2.1
Mozilla Firefox Esr 38.3.0
Mozilla Firefox Esr 38.1.1
Mozilla Firefox Esr 38.2.0
Mozilla Firefox Esr 38.0
Mozilla Firefox Esr 38.0.1
1 Article
NA
CVE-2011-2370
Mozilla Firefox prior to 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote malicious users to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors.
Mozilla Firefox 3.5.1
Mozilla Firefox 3.5.10
Mozilla Firefox 3.5.9
Mozilla Firefox 3.5.2
Mozilla Firefox 3.5.3
Mozilla Firefox 3.5.8
Mozilla Firefox 3.5
Mozilla Firefox 3.0.10
Mozilla Firefox 3.0.9
Mozilla Firefox 3.0.2
Mozilla Firefox 3.0.1
Mozilla Firefox 2.0.0.9
Mozilla Firefox 2.0.0.17
Mozilla Firefox 2.0.0.18
Mozilla Firefox 2.0.0.6
Mozilla Firefox 1.5.0.4
Mozilla Firefox 1.5.0.5
Mozilla Firefox 1.5.0.10
Mozilla Firefox 1.5.3
Mozilla Firefox 1.5
Mozilla Firefox 1.5.8
Mozilla Firefox 1.0.2
NA
CVE-2012-0468
The browser engine in Mozilla Firefox 4.x up to and including 11.0, Thunderbird 5.0 up to and including 11.0, and SeaMonkey prior to 2.9 allows remote malicious users to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vec...
Mozilla Firefox 4.0.1
Mozilla Firefox 4.0
Mozilla Firefox 6.0.2
Mozilla Firefox 6.0.1
Mozilla Firefox 10.0
Mozilla Firefox 10.0.1
Mozilla Firefox 5.0.1
Mozilla Firefox 6.0
Mozilla Firefox 9.0.1
Mozilla Firefox 9.0
Mozilla Firefox 5.0
Mozilla Firefox 8.0
Mozilla Firefox 8.0.1
Mozilla Firefox 7.0.1
Mozilla Firefox 7.0
Mozilla Firefox 10.0.2
Mozilla Firefox 11.0
Mozilla Thunderbird 6.0.2
Mozilla Thunderbird 7.0.1
Mozilla Thunderbird 7.0
Mozilla Thunderbird 10.0.4
Mozilla Thunderbird 11.0
NA
CVE-2012-0469
Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x up to and including 11.0, Firefox ESR 10.x prior to 10.0.4, Thunderbird 5.0 up to and including 11.0, Thunderbird ESR 10.x prior to 10.0.4, and SeaMonk...
Mozilla Firefox 4.0
Mozilla Firefox 5.0
Mozilla Firefox 8.0.1
Mozilla Firefox 9.0
Mozilla Firefox 7.0.1
Mozilla Firefox 8.0
Mozilla Firefox 11.0
Mozilla Firefox 4.0.1
Mozilla Firefox 5.0.1
Mozilla Firefox 6.0
Mozilla Firefox 6.0.1
Mozilla Firefox 9.0.1
Mozilla Firefox 10.0
Mozilla Firefox 6.0.2
Mozilla Firefox 7.0
Mozilla Firefox 10.0.1
Mozilla Firefox 10.0.2
Mozilla Firefox Esr 10.0
Mozilla Firefox Esr 10.0.1
Mozilla Firefox Esr 10.0.2
Mozilla Firefox Esr 10.0.3
Mozilla Thunderbird 6.0.2
NA
CVE-2012-0473
The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x up to and including 11.0, Firefox ESR 10.x prior to 10.0.4, Thunderbird 5.0 up to and including 11.0, Thunderbird ESR 10.x prior to 10.0.4, and SeaMonkey prior to 2.9 calls the FindMaxElementInSubArray function...
Mozilla Firefox 4.0
Mozilla Firefox 7.0
Mozilla Firefox 7.0.1
Mozilla Firefox 10.0.2
Mozilla Firefox 11.0
Mozilla Firefox 4.0.1
Mozilla Firefox 6.0.1
Mozilla Firefox 6.0.2
Mozilla Firefox 10.0
Mozilla Firefox 10.0.1
Mozilla Firefox 5.0.1
Mozilla Firefox 6.0
Mozilla Firefox 9.0
Mozilla Firefox 9.0.1
Mozilla Firefox 5.0
Mozilla Firefox 8.0
Mozilla Firefox 8.0.1
Mozilla Firefox Esr 10.0.3
Mozilla Firefox Esr 10.0.1
Mozilla Firefox Esr 10.0.2
Mozilla Firefox Esr 10.0
Mozilla Thunderbird 5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »