Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-49710 An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4. Firefox 139.0.4+ Fix from $2,3002025-06-11 CRITICAL 9.8 CVE-2025-49709 Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. Firefox 139.0.4+ Fix from $2,3002025-06-11 CRITICAL 9.8 CVE-2025-4918EPSS 9% An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fir… Firefox 115.23.1 / 128.10.1+ Fix from $2,3002025-05-17 CRITICAL 9.1 CVE-2025-4083 A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-… Firefox 115.23 / 128.10+ Fix from $2,3002025-04-29 CRITICAL 10.0 CVE-2025-2857 Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised ch… Firefox 115.21.1 / 128.8.1+ Fix from $2,3002025-03-27 CRITICAL 9.8 CVE-2025-1942 When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vuln… Firefox 136.0+ Fix from $2,3002025-03-04 CRITICAL 9.1 CVE-2025-1941 Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE… Firefox 136.0+ Fix from $2,3002025-03-04 CRITICAL 9.8 CVE-2025-1016 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of… Firefox 115.20.0 / 128.7.0+ Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2025-1017 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory co… Firefox 128.7.0 / 135.0+ Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2025-1020 Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 135.0+ Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2025-1009 An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir… Firefox 115.20.0 / 128.7.0+ Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2025-0247EPSS 9% Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 134.0+ Fix from $2,3002025-01-07 CRITICAL 9.8 CVE-2024-11698 A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was op… Firefox 128.5.0 / 133.0+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-11704 A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symme… Firefox 128.7.0 / 133.0+ Fix from $2,3002024-11-26 CRITICAL 9.1 CVE-2024-11705 `NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred… Firefox 133.0+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-11693 The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other … Firefox 128.5.0 / 133.0+ Fix from $2,3002024-11-26 CRITICAL 9.1 CVE-2024-10004 Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padloc… Firefox 131.2.0+ Fix from $2,3002024-10-15 CRITICAL 9.8 CVE-2024-9680 KEVEPSS 23% An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t… Firefox 115.16.0 / 115.16.1+ Fix from $2,3002024-10-09 CRITICAL 9.8 CVE-2024-9401 Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory… Firefox 115.16.0 / 128.3.0+ Fix from $2,3002024-10-01 CRITICAL 9.8 CVE-2024-9402 Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we p… Firefox 128.3.0 / 131.0+ Fix from $2,3002024-10-01 CRITICAL 9.8 CVE-2024-9392 A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox E… Firefox 115.6.0 / 128.3.0+ Fix from $2,3002024-10-01 CRITICAL 9.8 CVE-2024-8389 Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox Mitigation only Fix from $2,3002024-09-03 CRITICAL 9.8 CVE-2024-8381 A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This v… Firefox 115.15 / 128.2+ Fix from $2,3002024-09-03 CRITICAL 9.8 CVE-2024-8384 The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. Thi… Firefox 115.15 / 128.2+ Fix from $2,3002024-09-03 CRITICAL 9.8 CVE-2024-8385 A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulner… Firefox 128.2 / 130.0+ Fix from $2,3002024-09-03 CRITICAL 9.8 CVE-2024-8387 Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we p… Firefox Mitigation only Fix from $2,3002024-09-03 CRITICAL 9.6 CVE-2024-7519 Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a s… Firefox 115.14.0 / 129.0+ Fix from $2,3002024-08-06 CRITICAL 9.8 CVE-2024-6611 A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderb… Firefox 128.0+ Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-6602 A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu… Firefox 115.13 / 128.0+ Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-5695 If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered,… Firefox 127.0+ Fix from $2,3002024-06-11