16,510 vulnerabilities published in 2018
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vu
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabl
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This v
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buf
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c
Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulner
The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN pac
A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip i
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. T
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null deref
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-respons
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user co
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploit
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matc
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains im
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to crea
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS
A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base doma
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha
The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs,
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar.
The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Intern
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes
On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, s
Response header name interning does not have same-origin protections and these headers are stored in a global registry.
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This re
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with ano
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for la
A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content,
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin
A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially e
A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collec
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while
A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potent
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension ma
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but thi
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started