Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-14330 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun… Firefox 140.6.0 / 146.0+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14321 Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1… Firefox 140.6.0 / 146.0+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14324 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund… Firefox 115.31.0 / 140.6.0+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-13021 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13022 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13023 Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14… Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13024 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13026 Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14… Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-12380 Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel… Firefox 144.0.2+ Fix from $2,3002025-10-28 CRITICAL 9.8 CVE-2025-11719 Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory c… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11721 Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort th… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.1 CVE-2025-11717 When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11709 A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vuln… Firefox 115.29.0 / 140.4.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11710 A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom… Firefox 115.29.0 / 140.4.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11708 Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbir… Firefox 140.4.0 / 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-9187 Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 142.0+ Fix from $2,3002025-08-19 CRITICAL 9.8 CVE-2025-9179 An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but rep… Firefox 115.27.0 / 128.14.0+ Fix from $2,3002025-08-19 CRITICAL 9.8 CVE-2025-8042 Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14… Firefox 141.0+ Fix from $2,3002025-08-19 CRITICAL 9.8 CVE-2025-55031 Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range … Firefox 142.0+ Fix from $2,3002025-08-19 CRITICAL 9.8 CVE-2025-54143 Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent pag… Firefox 141.0+ Fix from $2,3002025-08-19 CRITICAL 9.1 CVE-2025-54145 The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR… Firefox 141.0+ Fix from $2,3002025-08-19 CRITICAL 9.8 CVE-2025-8043 Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141. Firefox 141.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-8044 Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 141.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-8031 The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln… Firefox 128.13.0 / 140.1.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-8038 Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thund… Firefox 140.1.0 / 141.0+ Fix from $2,3002025-07-22 CRITICAL 9.1 CVE-2025-8037 Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed coo… Firefox 140.1 / 141.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-8028 On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incor… Firefox 115.26.0 / 128.13.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-6433 If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the … Firefox 140.0+ Fix from $2,3002025-06-24 CRITICAL 9.8 CVE-2025-6424 A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox… Firefox 115.25.0 / 128.12.0+ Fix from $2,3002025-06-24 CRITICAL 9.1 CVE-2025-6427 An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the… Firefox 140.0+ Fix from $2,3002025-06-24