Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2025-14330

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14321

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14324

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…

Fix: 115.31.0 / 140.6.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-13021

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13022

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13023

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14…

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13024

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13026

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14…

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-12380

Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel…

Fix: 144.0.2+
Fix from $2,300 2025-10-28
Firefox CRITICAL 9.8
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory c…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11721

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort th…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.1
CVE-2025-11717

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vuln…

Fix: 115.29.0 / 140.4.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11710

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom…

Fix: 115.29.0 / 140.4.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbir…

Fix: 140.4.0 / 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-9187

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 142.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-9179

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but rep…

Fix: 115.27.0 / 128.14.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-8042

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-55031

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Fix: 142.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-54143

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent pag…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.1
CVE-2025-54145

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-8043

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

Fix: 141.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8044

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 141.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8031

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln…

Fix: 128.13.0 / 140.1.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8038

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thund…

Fix: 140.1.0 / 141.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.1
CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed coo…

Fix: 140.1 / 141.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8028

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incor…

Fix: 115.26.0 / 128.13.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the …

Fix: 140.0+
Fix from $2,300 2025-06-24
Firefox CRITICAL 9.8
CVE-2025-6424

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox…

Fix: 115.25.0 / 128.12.0+
Fix from $2,300 2025-06-24
Firefox CRITICAL 9.1
CVE-2025-6427

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the…

Fix: 140.0+
Fix from $2,300 2025-06-24