Vulnerabilities (CVE)

Filtered by vendor Mozilla Subscribe
Filtered by product Firefox
Total 2917 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-5266 1 Mozilla 1 Firefox 2025-09-23 N/A 4.3 MEDIUM
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
CVE-2025-4090 1 Mozilla 2 Firefox, Thunderbird 2025-09-23 N/A 5.3 MEDIUM
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability affects Firefox < 138 and Thunderbird < 138.
CVE-2025-4087 1 Mozilla 2 Firefox, Thunderbird 2025-09-23 N/A 4.8 MEDIUM
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.
CVE-2025-4918 1 Mozilla 2 Firefox, Thunderbird 2025-09-22 N/A 9.8 CRITICAL
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
CVE-2025-4093 1 Mozilla 2 Firefox, Thunderbird 2025-09-22 N/A 8.1 HIGH
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird < 128.10.
CVE-2025-4091 1 Mozilla 2 Firefox, Thunderbird 2025-09-22 N/A 8.1 HIGH
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.
CVE-2025-10536 1 Mozilla 2 Firefox, Thunderbird 2025-09-22 N/A 6.2 MEDIUM
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10537 1 Mozilla 2 Firefox, Thunderbird 2025-09-20 N/A 8.8 HIGH
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10527 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 7.1 HIGH
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10528 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 7.3 HIGH
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10529 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 6.5 MEDIUM
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10530 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 6.5 MEDIUM
This vulnerability affects Firefox < 143 and Thunderbird < 143.
CVE-2025-10531 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 5.4 MEDIUM
This vulnerability affects Firefox < 143 and Thunderbird < 143.
CVE-2025-10532 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 6.5 MEDIUM
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10533 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 8.8 HIGH
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10534 1 Mozilla 2 Firefox, Thunderbird 2025-09-19 N/A 8.1 HIGH
This vulnerability affects Firefox < 143 and Thunderbird < 143.
CVE-2025-10535 1 Mozilla 1 Firefox 2025-09-19 N/A 7.5 HIGH
This vulnerability affects Firefox < 143.
CVE-2025-8041 2 Google, Mozilla 2 Android, Firefox 2025-09-19 N/A 5.3 MEDIUM
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141.
CVE-2025-8042 2 Google, Mozilla 2 Android, Firefox 2025-09-19 N/A 9.8 CRITICAL
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.
CVE-2025-54143 1 Mozilla 1 Firefox 2025-08-21 N/A 9.8 CRITICAL
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.