Total
2917 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-5266 | 1 Mozilla | 1 Firefox | 2025-09-23 | N/A | 4.3 MEDIUM |
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | |||||
CVE-2025-4090 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-23 | N/A | 5.3 MEDIUM |
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability affects Firefox < 138 and Thunderbird < 138. | |||||
CVE-2025-4087 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-23 | N/A | 4.8 MEDIUM |
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10. | |||||
CVE-2025-4918 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-22 | N/A | 9.8 CRITICAL |
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2. | |||||
CVE-2025-4093 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-22 | N/A | 8.1 HIGH |
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird < 128.10. | |||||
CVE-2025-4091 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-22 | N/A | 8.1 HIGH |
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10. | |||||
CVE-2025-10536 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-22 | N/A | 6.2 MEDIUM |
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10537 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-20 | N/A | 8.8 HIGH |
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10527 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 7.1 HIGH |
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10528 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 7.3 HIGH |
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10529 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 6.5 MEDIUM |
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10530 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 6.5 MEDIUM |
This vulnerability affects Firefox < 143 and Thunderbird < 143. | |||||
CVE-2025-10531 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 5.4 MEDIUM |
This vulnerability affects Firefox < 143 and Thunderbird < 143. | |||||
CVE-2025-10532 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 6.5 MEDIUM |
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10533 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 8.8 HIGH |
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | |||||
CVE-2025-10534 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-09-19 | N/A | 8.1 HIGH |
This vulnerability affects Firefox < 143 and Thunderbird < 143. | |||||
CVE-2025-10535 | 1 Mozilla | 1 Firefox | 2025-09-19 | N/A | 7.5 HIGH |
This vulnerability affects Firefox < 143. | |||||
CVE-2025-8041 | 2 Google, Mozilla | 2 Android, Firefox | 2025-09-19 | N/A | 5.3 MEDIUM |
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141. | |||||
CVE-2025-8042 | 2 Google, Mozilla | 2 Android, Firefox | 2025-09-19 | N/A | 9.8 CRITICAL |
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141. | |||||
CVE-2025-54143 | 1 Mozilla | 1 Firefox | 2025-08-21 | N/A | 9.8 CRITICAL |
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141. |