Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-12380 Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel… Firefox 144.0.2+ Fix from $2,3002025-10-28 CRITICAL 9.8 CVE-2025-11719 Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory c… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11721 Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort th… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.1 CVE-2025-11717 When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las… Firefox 144.0+ Fix from $2,3002025-10-14 HIGH 8.1 CVE-2025-11720 The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied cont… Firefox 144.0+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-11718 When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visib… Firefox 144.0+ Fix from $1,6002025-10-14 CRITICAL 9.8 CVE-2025-11709 A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vuln… Firefox 115.29.0 / 140.4.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11710 A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom… Firefox 115.29.0 / 140.4.0+ Fix from $2,3002025-10-14 HIGH 8.8 CVE-2025-11714 Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showe… Firefox 115.29.0 / 140.4.0+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-11715 Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory… Firefox 140.4.0 / 144.0+ Fix from $1,9502025-10-14 HIGH 8.1 CVE-2025-11713 Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affe… Firefox 140.4.0 / 144.0+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-11711 There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 1… Firefox 115.29.0 / 140.4.0+ Fix from $1,6002025-10-14 MEDIUM 6.5 CVE-2025-11716 Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 1… Firefox 144.0+ Fix from $1,6002025-10-14 MEDIUM 6.1 CVE-2025-11712 A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served… Firefox 140.4.0 / 144.0+ Fix from $1,6002025-10-14 CRITICAL 9.8 CVE-2025-11708 Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbir… Firefox 140.4.0 / 144.0+ Fix from $2,3002025-10-14 HIGH 8.6 CVE-2025-11152 Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3. Firefox 143.0.3+ Fix from $1,9502025-09-30 HIGH 7.5 CVE-2025-11153 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. Firefox 143.0.3+ Fix from $1,9502025-09-30 HIGH 8.8 CVE-2025-10537 Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory… Firefox 140.3.0 / 143.0+ Fix from $1,9502025-09-16 HIGH 8.1 CVE-2025-10534 Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. Firefox 143.0+ Fix from $1,9502025-09-16 HIGH 7.5 CVE-2025-10535 Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143. Firefox 143.0+ Fix from $1,9502025-09-16 MEDIUM 6.2 CVE-2025-10536 Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund… Firefox 140.3.0 / 143.0+ Fix from $1,6002025-09-16 HIGH 8.8 CVE-2025-10533 Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thund… Firefox 115.28.0 / 140.3+ Fix from $1,9502025-09-16 MEDIUM 6.5 CVE-2025-10532 Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and T… Firefox 140.3.0 / 143.0+ Fix from $1,6002025-09-16 MEDIUM 6.5 CVE-2025-10530 Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143. Firefox 143.0+ Fix from $1,6002025-09-16 MEDIUM 5.4 CVE-2025-10531 Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. Firefox 143.0+ Fix from $1,6002025-09-16 HIGH 7.3 CVE-2025-10528 Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox E… Firefox 140.3.0 / 143.0+ Fix from $1,9502025-09-16 MEDIUM 6.5 CVE-2025-10529 Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 1… Firefox 140.3.0 / 143.0+ Fix from $1,6002025-09-16 HIGH 7.1 CVE-2025-10527 Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird… Firefox 140.3.0 / 143.0+ Fix from $1,9502025-09-16 MEDIUM 6.5 CVE-2025-10290 Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing a… Firefox Focus 143.0+ Fix from $1,6002025-09-16 CRITICAL 9.8 CVE-2025-9187 Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 142.0+ Fix from $2,3002025-08-19