Vulnerabilities
Tracked app vulnerabilities
11,280 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,280
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2017-7846
HIGH 8.8
1 app
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard… |
|
CVE-2017-7845
HIGH 8.8
1 app
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an inco… |
|
CVE-2017-7814
HIGH 7.8
1 app
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its bl… |
|
CVE-2017-7807
HIGH 8.1
1 app
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requir… |
|
CVE-2017-7805
HIGH 7.5
1 app
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the han… |
|
CVE-2017-7804
HIGH 7.5
1 app
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary d… |
|
CVE-2017-7803
HIGH 7.5
1 app
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of C… |
|
CVE-2017-7787
HIGH 7.5
1 app
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page… |
|
CVE-2017-7765
HIGH 7.5
1 app
The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, t… |
|
CVE-2017-7755
HIGH 7.8
1 app
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged e… |
|
CVE-2017-7754
HIGH 7.5
1 app
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52… |
|
CVE-2017-7752
HIGH 8.8
1 app
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This resul… |
|
CVE-2017-5467
HIGH 7.5
1 app
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thu… |
|
CVE-2017-5454
HIGH 7.5
1 app
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker thr… |
|
CVE-2017-5449
HIGH 7.5
1 app
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects … |
|
CVE-2017-5445
HIGH 7.5
1 app
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the readi… |
|
CVE-2017-5444
HIGH 7.5
1 app
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows fo… |
|
CVE-2017-5436
HIGH 8.8
1 app
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issu… |
|
CVE-2017-5425
HIGH 7.5
1 app
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subd… |
|
CVE-2017-5422
HIGH 7.5
1 app
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink i… |
|
CVE-2017-5421
HIGH 7.5
1 app
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loade… |
|
CVE-2017-5419
HIGH 7.5
1 app
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the ope… |
|
CVE-2017-5416
HIGH 7.5
1 app
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability … |
|
CVE-2017-5412
HIGH 7.5
1 app
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52. |
|
CVE-2017-5411
HIGH 7.5
1 app
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while st… |
|
CVE-2017-5406
HIGH 7.5
1 app
A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulne… |
|
CVE-2017-5378
HIGH 7.5
1 app
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, an… |
|
CVE-2016-9905
HIGH 8.8
1 app
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbir… |
|
CVE-2016-9904
HIGH 7.5
1 app
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be u… |
|
CVE-2016-9900
HIGH 7.5
1 app
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cros… |
|
CVE-2016-9897
HIGH 7.5
1 app
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vuln… |
|
CVE-2016-9079
HIGH 7.5
KEV
1 app
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2016-9066
HIGH 7.5
1 app
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability… |
|
CVE-2016-5296
HIGH 7.5
1 app
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability a… |
|
CVE-2018-9409
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9372
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9371
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9370
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9369
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9368
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9367
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9366
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9363
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9362
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9361
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9360
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9359
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9358
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9348
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9347
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |