Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.8 CVE-2025-13020 Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-13014 Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and… Firefox 115.30.0 / 140.5.0+ Fix from $1,9502025-11-11 CRITICAL 9.8 CVE-2025-12380 Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel… Firefox 144.0.2+ Fix from $2,3002025-10-28 CRITICAL 9.8 CVE-2025-11719 Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory c… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11708 Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbir… Firefox 140.4.0 / 144.0+ Fix from $2,3002025-10-14 HIGH 7.1 CVE-2025-10527 Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird… Firefox 140.3.0 / 143.0+ Fix from $1,9502025-09-16 CRITICAL 9.8 CVE-2025-6424 A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox… Firefox 115.25.0 / 128.12.0+ Fix from $2,3002025-06-24 HIGH 8.1 CVE-2025-3030 Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory co… Firefox 128.8.0 / 136.0+ Fix from $1,9502025-04-01 MEDIUM 6.5 CVE-2025-3028 JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox … Firefox 115.22.0 / 128.9.0+ Fix from $1,6002025-04-01 HIGH 8.8 CVE-2025-1930 On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could … Firefox 115.21.0 / 128.8+ Fix from $1,9502025-03-04 HIGH 7.5 CVE-2025-1931 It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This … Firefox 115.21.0 / 128.8.0+ Fix from $1,9502025-03-04 HIGH 7.5 CVE-2025-1012 A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox … Firefox 115.20.0 / 128.7.0+ Fix from $1,9502025-02-04 CRITICAL 9.8 CVE-2025-1009 An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir… Firefox 115.20.0 / 128.7.0+ Fix from $2,3002025-02-04 HIGH 8.8 CVE-2025-1010 An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed… Firefox 115.20.0 / 128.7.0+ Fix from $1,9502025-02-04 MEDIUM 5.3 CVE-2025-0238 Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vuln… Firefox 115.19.0 / 128.6+ Fix from $1,6002025-01-07 HIGH 7.5 CVE-2024-10459 An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects… Firefox 115.17 / 128.4.0+ Fix from $1,9502024-10-29 CRITICAL 9.8 CVE-2024-9680 KEVEPSS 23% An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t… Firefox 115.16.0 / 115.16.1+ Fix from $2,3002024-10-09 MEDIUM 6.5 CVE-2024-8394 When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.… Thunderbird 128.2.0+ Fix from $1,6002024-09-06 CRITICAL 9.8 CVE-2024-8384 The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. Thi… Firefox 115.15 / 128.2+ Fix from $2,3002024-09-03 HIGH 8.8 CVE-2024-7527 Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, … Firefox 115.14.0 / 129.0+ Fix from $1,9502024-08-06 HIGH 8.8 CVE-2024-7528 Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128… Firefox 128.1.0 / 129.0+ Fix from $1,9502024-08-06 HIGH 8.8 CVE-2024-7530 Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129. Firefox 129.0+ Fix from $1,9502024-08-06 HIGH 7.5 CVE-2024-5702 Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < … Firefox 115.12 / 125.0+ Fix from $1,9502024-06-11 HIGH 8.1 CVE-2024-5688 If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Fi… Firefox 115.12 / 127.0+ Fix from $1,9502024-06-11 HIGH 7.5 CVE-2024-5694 An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerabili… Firefox 127.0+ Fix from $1,9502024-06-11 HIGH 8.8 CVE-2024-4777 Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we… Firefox 115.11.0 / 126.0+ Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-4770 When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox … Firefox 115.11.0 / 126.0+ Fix from $1,9502024-05-14 HIGH 8.6 CVE-2024-4771 A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially… Firefox 126.0+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-4764 Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126. Firefox 126.0+ Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-3856 A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 12… Firefox 125.0+ Fix from $1,9502024-04-16