Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Firefox HIGH 8.8
CVE-2025-13020

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.8
CVE-2025-13014

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and…

Fix: 115.30.0 / 140.5.0+
Fix from $1,950 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-12380

Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel…

Fix: 144.0.2+
Fix from $2,300 2025-10-28
Firefox CRITICAL 9.8
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory c…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbir…

Fix: 140.4.0 / 144.0+
Fix from $2,300 2025-10-14
Firefox HIGH 7.1
CVE-2025-10527

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird…

Fix: 140.3.0 / 143.0+
Fix from $1,950 2025-09-16
Firefox CRITICAL 9.8
CVE-2025-6424

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox…

Fix: 115.25.0 / 128.12.0+
Fix from $2,300 2025-06-24
Firefox HIGH 8.1
CVE-2025-3030

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory co…

Fix: 128.8.0 / 136.0+
Fix from $1,950 2025-04-01
Firefox MEDIUM 6.5
CVE-2025-3028

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox …

Fix: 115.22.0 / 128.9.0+
Fix from $1,600 2025-04-01
Firefox HIGH 8.8
CVE-2025-1930

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could …

Fix: 115.21.0 / 128.8+
Fix from $1,950 2025-03-04
Firefox HIGH 7.5
CVE-2025-1931

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This …

Fix: 115.21.0 / 128.8.0+
Fix from $1,950 2025-03-04
Firefox HIGH 7.5
CVE-2025-1012

A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox …

Fix: 115.20.0 / 128.7.0+
Fix from $1,950 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1009

An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir…

Fix: 115.20.0 / 128.7.0+
Fix from $2,300 2025-02-04
Firefox HIGH 8.8
CVE-2025-1010

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed…

Fix: 115.20.0 / 128.7.0+
Fix from $1,950 2025-02-04
Firefox MEDIUM 5.3
CVE-2025-0238

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vuln…

Fix: 115.19.0 / 128.6+
Fix from $1,600 2025-01-07
Firefox HIGH 7.5
CVE-2024-10459

An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects…

Fix: 115.17 / 128.4.0+
Fix from $1,950 2024-10-29
Firefox CRITICAL 9.8
CVE-2024-9680 KEVEPSS 23%

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t…

Fix: 115.16.0 / 115.16.1+
Fix from $2,300 2024-10-09
Thunderbird MEDIUM 6.5
CVE-2024-8394

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.…

Fix: 128.2.0+
Fix from $1,600 2024-09-06
Firefox CRITICAL 9.8
CVE-2024-8384

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. Thi…

Fix: 115.15 / 128.2+
Fix from $2,300 2024-09-03
Firefox HIGH 8.8
CVE-2024-7527

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, …

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7528

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128…

Fix: 128.1.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7530

Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

Fix: 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 7.5
CVE-2024-5702

Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < …

Fix: 115.12 / 125.0+
Fix from $1,950 2024-06-11
Firefox HIGH 8.1
CVE-2024-5688

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Fi…

Fix: 115.12 / 127.0+
Fix from $1,950 2024-06-11
Firefox HIGH 7.5
CVE-2024-5694

An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerabili…

Fix: 127.0+
Fix from $1,950 2024-06-11
Firefox HIGH 8.8
CVE-2024-4777

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we…

Fix: 115.11.0 / 126.0+
Fix from $1,950 2024-05-14
Firefox HIGH 8.8
CVE-2024-4770

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox …

Fix: 115.11.0 / 126.0+
Fix from $1,950 2024-05-14
Firefox HIGH 8.6
CVE-2024-4771

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially…

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox CRITICAL 9.8
CVE-2024-4764

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

Fix: 126.0+
Fix from $2,300 2024-05-14
Firefox HIGH 8.8
CVE-2024-3856

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 12…

Fix: 125.0+
Fix from $1,950 2024-04-16