Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2025-9185 Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 a… Firefox 115.27.0 / 128.14.0+ Fix from $1,9502025-08-19 MEDIUM 6.5 CVE-2025-9186 Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142. Firefox 142.0+ Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-9179 An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but rep… Firefox 115.27.0 / 128.14.0+ Fix from $2,3002025-08-19 HIGH 8.1 CVE-2025-9180 Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, F… Firefox 115.27.0 / 128.14.0+ Fix from $1,9502025-08-19 HIGH 8.1 CVE-2025-9184 Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory… Firefox 140.2.0 / 142.0+ Fix from $1,9502025-08-19 HIGH 7.5 CVE-2025-9182 Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderb… Firefox 140.2.0 / 142.0+ Fix from $1,9502025-08-19 MEDIUM 6.5 CVE-2025-9181 Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderb… Firefox 128.14.0 / 140.2.0+ Fix from $1,6002025-08-19 MEDIUM 6.5 CVE-2025-9183 Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2. Firefox 140.2.0 / 142.0+ Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-8042 Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14… Firefox 141.0+ Fix from $2,3002025-08-19 MEDIUM 5.3 CVE-2025-8041 In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed i… Firefox 141.0+ Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-55031 Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range … Firefox 142.0+ Fix from $2,3002025-08-19 HIGH 7.5 CVE-2025-55029 Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed i… Firefox 142.0+ Fix from $1,9502025-08-19 MEDIUM 6.1 CVE-2025-55030 Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downlo… Firefox 142.0+ Fix from $1,6002025-08-19 MEDIUM 6.1 CVE-2025-55032 Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin… Firefox Focus 142.0+ Fix from $1,6002025-08-19 MEDIUM 6.1 CVE-2025-55033 Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vuln… Firefox Focus 142.0+ Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-54143 Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent pag… Firefox 141.0+ Fix from $2,3002025-08-19 CRITICAL 9.1 CVE-2025-54145 The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR… Firefox 141.0+ Fix from $2,3002025-08-19 MEDIUM 6.5 CVE-2025-55028 Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service atta… Firefox 142.0+ Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-54144 The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p… Firefox 141.0+ Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-8043 Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141. Firefox 141.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-8044 Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 141.0+ Fix from $2,3002025-07-22 HIGH 8.8 CVE-2025-8040 Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory… Firefox 140.1 / 141.0+ Fix from $1,9502025-07-22 HIGH 8.1 CVE-2025-8039 In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir… Firefox 140.1 / 141.0+ Fix from $1,9502025-07-22 CRITICAL 9.8 CVE-2025-8031 The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln… Firefox 128.13.0 / 140.1.0+ Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2025-8038 Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thund… Firefox 140.1.0 / 141.0+ Fix from $2,3002025-07-22 CRITICAL 9.1 CVE-2025-8037 Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed coo… Firefox 140.1 / 141.0+ Fix from $2,3002025-07-22 HIGH 8.8 CVE-2025-8034 Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 a… Firefox 115.26.0 / 128.13.0+ Fix from $1,9502025-07-22 HIGH 8.8 CVE-2025-8035 Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. … Firefox 128.13.0 / 140.1.0+ Fix from $1,9502025-07-22 HIGH 8.1 CVE-2025-8029 Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Fire… Firefox 128.13.0 / 140.1.0+ Fix from $1,9502025-07-22 HIGH 8.1 CVE-2025-8030 Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was … Firefox 128.13.0 / 140.1.0+ Fix from $1,9502025-07-22