Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-49710
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.
Firefox
139.0.4+
CRITICAL 9.8
CVE-2025-49709
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
Firefox
139.0.4+
CRITICAL 9.8
CVE-2025-4918EPSS 9%
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fir…
Firefox
115.23.1 / 128.10.1+
CRITICAL 9.1
CVE-2025-4083
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-…
Firefox
115.23 / 128.10+
CRITICAL 10.0
CVE-2025-2857
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised ch…
Firefox
115.21.1 / 128.8.1+
CRITICAL 9.8
CVE-2025-1942
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vuln…
Firefox
136.0+
CRITICAL 9.1
CVE-2025-1941
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE…
Firefox
136.0+
CRITICAL 9.8
CVE-2025-1016
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of…
Firefox
115.20.0 / 128.7.0+
CRITICAL 9.8
CVE-2025-1017
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory co…
Firefox
128.7.0 / 135.0+
CRITICAL 9.8
CVE-2025-1020
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
Firefox
135.0+
CRITICAL 9.8
CVE-2025-1009
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir…
Firefox
115.20.0 / 128.7.0+
CRITICAL 9.8
CVE-2025-0247EPSS 9%
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
Firefox
134.0+
CRITICAL 9.8
CVE-2024-11698
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was op…
Firefox
128.5.0 / 133.0+
CRITICAL 9.8
CVE-2024-11704
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symme…
Firefox
128.7.0 / 133.0+
CRITICAL 9.1
CVE-2024-11705
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred…
Firefox
133.0+
CRITICAL 9.8
CVE-2024-11693
The executable file warning was not presented when downloading .library-ms files.
*Note: This issue only affected Windows operating systems. Other …
Firefox
128.5.0 / 133.0+
CRITICAL 9.1
CVE-2024-10004
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padloc…
Firefox
131.2.0+
CRITICAL 9.8
CVE-2024-9680 KEVEPSS 23%
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t…
Firefox
115.16.0 / 115.16.1+
CRITICAL 9.8
CVE-2024-9401
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory…
Firefox
115.16.0 / 128.3.0+
CRITICAL 9.8
CVE-2024-9402
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we p…
Firefox
128.3.0 / 131.0+
CRITICAL 9.8
CVE-2024-9392
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox E…
Firefox
115.6.0 / 128.3.0+
CRITICAL 9.8
CVE-2024-8389
Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…
Firefox
Mitigation only
CRITICAL 9.8
CVE-2024-8381
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This v…
Firefox
115.15 / 128.2+
CRITICAL 9.8
CVE-2024-8384
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. Thi…
Firefox
115.15 / 128.2+
CRITICAL 9.8
CVE-2024-8385
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulner…
Firefox
128.2 / 130.0+
CRITICAL 9.8
CVE-2024-8387
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we p…
Firefox
Mitigation only
CRITICAL 9.6
CVE-2024-7519
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a s…
Firefox
115.14.0 / 129.0+
CRITICAL 9.8
CVE-2024-6611
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderb…
Firefox
128.0+
CRITICAL 9.8
CVE-2024-6602
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu…
Firefox
115.13 / 128.0+
CRITICAL 9.8
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered,…
Firefox
127.0+