Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.1
CVE-2025-9185

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 a…

Fix: 115.27.0 / 128.14.0+
Fix from $1,950 2025-08-19
Firefox MEDIUM 6.5
CVE-2025-9186

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-9179

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but rep…

Fix: 115.27.0 / 128.14.0+
Fix from $2,300 2025-08-19
Firefox HIGH 8.1
CVE-2025-9180

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, F…

Fix: 115.27.0 / 128.14.0+
Fix from $1,950 2025-08-19
Firefox HIGH 8.1
CVE-2025-9184

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory…

Fix: 140.2.0 / 142.0+
Fix from $1,950 2025-08-19
Firefox HIGH 7.5
CVE-2025-9182

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderb…

Fix: 140.2.0 / 142.0+
Fix from $1,950 2025-08-19
Firefox MEDIUM 6.5
CVE-2025-9181

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderb…

Fix: 128.14.0 / 140.2.0+
Fix from $1,600 2025-08-19
Firefox MEDIUM 6.5
CVE-2025-9183

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

Fix: 140.2.0 / 142.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-8042

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox MEDIUM 5.3
CVE-2025-8041

In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed i…

Fix: 141.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-55031

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Fix: 142.0+
Fix from $2,300 2025-08-19
Firefox HIGH 7.5
CVE-2025-55029

Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed i…

Fix: 142.0+
Fix from $1,950 2025-08-19
Firefox MEDIUM 6.1
CVE-2025-55030

Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downlo…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox Focus MEDIUM 6.1
CVE-2025-55032

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox Focus MEDIUM 6.1
CVE-2025-55033

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vuln…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-54143

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent pag…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox CRITICAL 9.1
CVE-2025-54145

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox MEDIUM 6.5
CVE-2025-55028

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service atta…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox MEDIUM 5.4
CVE-2025-54144

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p…

Fix: 141.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.8
CVE-2025-8043

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

Fix: 141.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8044

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 141.0+
Fix from $2,300 2025-07-22
Firefox HIGH 8.8
CVE-2025-8040

Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory…

Fix: 140.1 / 141.0+
Fix from $1,950 2025-07-22
Firefox HIGH 8.1
CVE-2025-8039

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir…

Fix: 140.1 / 141.0+
Fix from $1,950 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8031

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln…

Fix: 128.13.0 / 140.1.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.8
CVE-2025-8038

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thund…

Fix: 140.1.0 / 141.0+
Fix from $2,300 2025-07-22
Firefox CRITICAL 9.1
CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed coo…

Fix: 140.1 / 141.0+
Fix from $2,300 2025-07-22
Firefox HIGH 8.8
CVE-2025-8034

Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 a…

Fix: 115.26.0 / 128.13.0+
Fix from $1,950 2025-07-22
Firefox HIGH 8.8
CVE-2025-8035

Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. …

Fix: 128.13.0 / 140.1.0+
Fix from $1,950 2025-07-22
Firefox HIGH 8.1
CVE-2025-8029

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Fire…

Fix: 128.13.0 / 140.1.0+
Fix from $1,950 2025-07-22
Firefox HIGH 8.1
CVE-2025-8030

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was …

Fix: 128.13.0 / 140.1.0+
Fix from $1,950 2025-07-22