Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2025-1942

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vuln…

Fix: 136.0+
Fix from $2,300 2025-03-04
Firefox CRITICAL 9.1
CVE-2025-1941

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE…

Fix: 136.0+
Fix from $2,300 2025-03-04
Firefox HIGH 8.2
CVE-2025-1943

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 136.0+
Fix from $1,950 2025-03-04
Firefox MEDIUM 5.4
CVE-2025-27426

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in …

Fix: 136.0+
Fix from $1,600 2025-03-04
Firefox HIGH 8.1
CVE-2025-1932

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and la…

Fix: 128.8.0 / 136.0+
Fix from $1,950 2025-03-04
Firefox HIGH 7.6
CVE-2025-1933

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treat…

Fix: 115.21.0 / 128.8+
Fix from $1,950 2025-03-04
Firefox HIGH 7.5
CVE-2025-1937

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed e…

Fix: 115.21.0 / 128.8.0+
Fix from $1,950 2025-03-04
Firefox HIGH 7.3
CVE-2025-1936

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the ar…

Fix: 128.8.0 / 136.0+
Fix from $1,950 2025-03-04
Firefox HIGH 7.1
CVE-2025-1940

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launch…

Fix: 136.0+
Fix from $1,950 2025-03-04
Firefox MEDIUM 6.5
CVE-2025-1934

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the eng…

Fix: 128.8.0 / 136.0+
Fix from $1,600 2025-03-04
Firefox MEDIUM 6.5
CVE-2025-1938

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory co…

Fix: 128.7.0 / 135.0+
Fix from $1,600 2025-03-04
Firefox HIGH 8.8
CVE-2025-1930

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could …

Fix: 115.21.0 / 128.8+
Fix from $1,950 2025-03-04
Firefox HIGH 7.5
CVE-2025-1931

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This …

Fix: 115.21.0 / 128.8.0+
Fix from $1,950 2025-03-04
Firefox MEDIUM 6.5
CVE-2025-1414

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 135.0.1+
Fix from $1,600 2025-02-18
Firefox CRITICAL 9.8
CVE-2025-1016

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of…

Fix: 115.20.0 / 128.7.0+
Fix from $2,300 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1017

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory co…

Fix: 128.7.0 / 135.0+
Fix from $2,300 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1020

Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 135.0+
Fix from $2,300 2025-02-04
Firefox HIGH 8.8
CVE-2025-1014

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fi…

Fix: 128.7.0 / 135.0+
Fix from $1,950 2025-02-04
Firefox HIGH 7.5
CVE-2025-1012

A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox …

Fix: 115.20.0 / 128.7.0+
Fix from $1,950 2025-02-04
Firefox MEDIUM 6.5
CVE-2025-1013

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy lea…

Fix: 128.7.0 / 135.0+
Fix from $1,600 2025-02-04
Thunderbird MEDIUM 5.4
CVE-2025-1015

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containin…

Fix: 128.7.0+
Fix from $1,600 2025-02-04
Firefox MEDIUM 5.3
CVE-2025-1018

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a po…

Fix: 135.0+
Fix from $1,600 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1009

An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir…

Fix: 115.20.0 / 128.7.0+
Fix from $2,300 2025-02-04
Firefox HIGH 8.8
CVE-2025-1010

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed…

Fix: 115.20.0 / 128.7.0+
Fix from $1,950 2025-02-04
Firefox HIGH 8.8
CVE-2025-1011

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution…

Fix: 128.7.0 / 135.0+
Fix from $1,950 2025-02-04
Thunderbird MEDIUM 6.5
CVE-2025-0510

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-4904…

Fix: 128.7.0 / 135.0+
Fix from $1,600 2025-02-04
Firefox MEDIUM 6.5
CVE-2025-23109

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Fir…

Fix: 134.0+
Fix from $1,600 2025-01-11
Firefox CRITICAL 9.8
CVE-2025-0247EPSS 9%

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 134.0+
Fix from $2,300 2025-01-07
Firefox MEDIUM 6.5
CVE-2025-0246

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other ope…

Fix: 134.0+
Fix from $1,600 2025-01-07
Firefox MEDIUM 5.3
CVE-2025-0244EPSS 7%

When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. …

Fix: 134.0+
Fix from $1,600 2025-01-07