All vulnerabilities
1315 / 1315
Sort
9.6
CVE-2023-4863AST KEV
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allo…
2023-01-01KEV
EPSS99.7%
pct 99
7.3
CVE-2016-9079DEB KEV
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this v…
2016-01-01KEV
EPSS87.9%
pct 99
5.9
CVE-2013-2566CVE
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, w…
2013-01-01Pre-auth
EPSS84.4%
pct 99
9.8
CVE-2014-1511DEB
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonk…
2014-01-01Pre-auth
EPSS83.6%
pct 99
9.8
CVE-2010-3765DEB KEV
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 a…
2010-01-01KEV
EPSS83.3%
pct 99
9.8
CVE-2014-1510DEB
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunde…
2014-01-01Pre-auth
EPSS82.3%
pct 99
7.5
CVE-2006-3677DEB
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execut…
2006-01-01
EPSS77.3%
pct 99
6.8
CVE-2011-2371DEB
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x throu…
2011-01-01
EPSS75.7%
pct 99
6.8
CVE-2011-3026DEB
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attacker…
2011-01-01
EPSS73.4%
pct 99
6.8
CVE-2013-0758DEB
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbir…
2013-01-01
EPSS73.4%
pct 99
7.5
CVE-2024-4367ANC
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript …
2024-01-01Pre-auth
EPSS72.6%
pct 99
6.8
CVE-2011-0073DEB
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not pr…
2011-01-01
EPSS70.0%
pct 99
8.8
CVE-2013-1690DEB KEV
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thu…
2013-01-01KEV
EPSS69.2%
pct 99
5.0
CVE-2005-2265DEB
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers …
2005-01-01
EPSS68.1%
pct 99
5.1
CVE-2015-0816DEB
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not p…
2015-01-01
EPSS67.1%
pct 99
10.0
CVE-2019-11708AST KEV
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and pa…
2019-01-01KEV
EPSS55.9%
pct 98
6.8
CVE-2013-0753DEB
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer compo…
2013-01-01
EPSS51.3%
pct 98
6.8
CVE-2007-0009DEB
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) bef…
2007-01-01
EPSS50.4%
pct 98
8.8
CVE-2019-17026AST KEV
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to …
2019-01-01KEV
EPSS46.6%
pct 98
10.0
CVE-2008-0016DEB
Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.1…
2008-01-01
EPSS43.9%
pct 98
9.8
CVE-2010-1205DEB
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progre…
2010-01-01Pre-auth
EPSS43.4%
pct 98
6.8
CVE-2012-3993DEB
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x…
2012-01-01
EPSS42.6%
pct 98
8.8
CVE-2020-26950AST
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions res…
2020-01-01Pre-auth
EPSS42.6%
pct 98
6.8
CVE-2013-1710DEB
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before…
2013-01-01
EPSS40.4%
pct 98
8.8
CVE-2019-11707AST KEV
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in …
2019-01-01KEV
EPSS38.0%
pct 98
6.8
CVE-2011-3659DEB
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird …
2011-01-01
EPSS36.5%
pct 98
8.8
CVE-2023-5217AST KEV
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and lib…
2023-01-01KEV
EPSS34.4%
pct 98
9.8
CVE-2022-25236AST
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator …
2022-01-01Pre-auth
EPSS33.9%
pct 98
9.8
CVE-2017-5375DEB
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential mem…
2017-01-01Pre-auth
EPSS33.4%
pct 98
7.5
CVE-2024-9680ANC KEV
An attacker was able to achieve code execution in the content process by exploiting a use-after…
2024-01-01KEV
EPSS32.6%
pct 98
6.8
CVE-2014-1512DEB
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefo…
2014-01-01
EPSS31.4%
pct 98
8.8
CVE-2016-1960DEB
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox…
2016-01-01Pre-auth
EPSS31.0%
pct 98
8.8
CVE-2019-9810AST
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead…
2019-01-01Pre-auth
EPSS29.5%
pct 97
6.8
CVE-2009-0689DEB
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka…
2009-01-01
EPSS28.2%
pct 97
8.8
CVE-2022-1802AST
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype p…
2022-01-01Pre-auth
EPSS26.7%
pct 97
8.8
CVE-2022-2200AST
If an object prototype was corrupted by an attacker, they would have been able to set undesired…
2022-01-01Pre-auth
EPSS23.9%
pct 97
9.8
CVE-2016-9899DEB
Use-after-free while manipulating DOM events and removing audio elements due to errors in the h…
2016-01-01Pre-auth
EPSS21.4%
pct 97
9.8
CVE-2018-5159AST
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without…
2018-01-01Pre-auth
EPSS21.3%
pct 97
7.5
CVE-2005-2871DEB
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and ear…
2005-01-01
EPSS21.1%
pct 97
8.8
CVE-2023-6856AST
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on…
2023-01-01Pre-auth
EPSS20.5%
pct 97
Select a vulnerability on the left to open the preview.