Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2025-12380

Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel…

Fix: 144.0.2+
Fix from $2,300 2025-10-28
Firefox CRITICAL 9.8
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory c…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11721

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort th…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.1
CVE-2025-11717

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox HIGH 8.1
CVE-2025-11720

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied cont…

Fix: 144.0+
Fix from $1,950 2025-10-14
Firefox MEDIUM 6.5
CVE-2025-11718

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visib…

Fix: 144.0+
Fix from $1,600 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vuln…

Fix: 115.29.0 / 140.4.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11710

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom…

Fix: 115.29.0 / 140.4.0+
Fix from $2,300 2025-10-14
Firefox HIGH 8.8
CVE-2025-11714

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showe…

Fix: 115.29.0 / 140.4.0+
Fix from $1,950 2025-10-14
Firefox HIGH 8.8
CVE-2025-11715

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory…

Fix: 140.4.0 / 144.0+
Fix from $1,950 2025-10-14
Firefox HIGH 8.1
CVE-2025-11713

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affe…

Fix: 140.4.0 / 144.0+
Fix from $1,950 2025-10-14
Firefox MEDIUM 6.5
CVE-2025-11711

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 1…

Fix: 115.29.0 / 140.4.0+
Fix from $1,600 2025-10-14
Firefox MEDIUM 6.5
CVE-2025-11716

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 1…

Fix: 144.0+
Fix from $1,600 2025-10-14
Firefox MEDIUM 6.1
CVE-2025-11712

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served…

Fix: 140.4.0 / 144.0+
Fix from $1,600 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbir…

Fix: 140.4.0 / 144.0+
Fix from $2,300 2025-10-14
Firefox HIGH 8.6
CVE-2025-11152

Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.

Fix: 143.0.3+
Fix from $1,950 2025-09-30
Firefox HIGH 7.5
CVE-2025-11153

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.

Fix: 143.0.3+
Fix from $1,950 2025-09-30
Firefox HIGH 8.8
CVE-2025-10537

Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory…

Fix: 140.3.0 / 143.0+
Fix from $1,950 2025-09-16
Firefox HIGH 8.1
CVE-2025-10534

Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

Fix: 143.0+
Fix from $1,950 2025-09-16
Firefox HIGH 7.5
CVE-2025-10535

Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.

Fix: 143.0+
Fix from $1,950 2025-09-16
Firefox MEDIUM 6.2
CVE-2025-10536

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund…

Fix: 140.3.0 / 143.0+
Fix from $1,600 2025-09-16
Firefox HIGH 8.8
CVE-2025-10533

Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thund…

Fix: 115.28.0 / 140.3+
Fix from $1,950 2025-09-16
Firefox MEDIUM 6.5
CVE-2025-10532

Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and T…

Fix: 140.3.0 / 143.0+
Fix from $1,600 2025-09-16
Firefox MEDIUM 6.5
CVE-2025-10530

Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

Fix: 143.0+
Fix from $1,600 2025-09-16
Firefox MEDIUM 5.4
CVE-2025-10531

Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

Fix: 143.0+
Fix from $1,600 2025-09-16
Firefox HIGH 7.3
CVE-2025-10528

Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox E…

Fix: 140.3.0 / 143.0+
Fix from $1,950 2025-09-16
Firefox MEDIUM 6.5
CVE-2025-10529

Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 1…

Fix: 140.3.0 / 143.0+
Fix from $1,600 2025-09-16
Firefox HIGH 7.1
CVE-2025-10527

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird…

Fix: 140.3.0 / 143.0+
Fix from $1,950 2025-09-16
Firefox Focus MEDIUM 6.5
CVE-2025-10290

Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing a…

Fix: 143.0+
Fix from $1,600 2025-09-16
Firefox CRITICAL 9.8
CVE-2025-9187

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 142.0+
Fix from $2,300 2025-08-19