Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2025-8032 XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ES… Firefox 128.13.0 / 140.1.0+ Fix from $1,9502025-07-22 HIGH 8.1 CVE-2025-8036 Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fix… Firefox 140.1.0 / 141.0+ Fix from $1,9502025-07-22 MEDIUM 6.5 CVE-2025-8033 The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability wa… Firefox 115.26.0 / 128.13.0+ Fix from $1,6002025-07-22 CRITICAL 9.8 CVE-2025-8028 On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incor… Firefox 115.26.0 / 128.13.0+ Fix from $2,3002025-07-22 MEDIUM 6.5 CVE-2025-8027 On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. T… Firefox 115.26.0 / 128.13.0+ Fix from $1,6002025-07-22 MEDIUM 6.5 CVE-2025-6703 Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2. Neqo after 0.13.2 Fix from $1,6002025-06-26 CRITICAL 9.8 CVE-2025-6433 If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the … Firefox 140.0+ Fix from $2,3002025-06-24 HIGH 8.6 CVE-2025-6432 When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not… Firefox 140.0+ Fix from $1,9502025-06-24 HIGH 8.1 CVE-2025-6435 If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.downl… Firefox 140.0+ Fix from $1,9502025-06-24 HIGH 8.1 CVE-2025-6436 Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 140.0+ Fix from $1,9502025-06-24 MEDIUM 6.5 CVE-2025-6431 When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have b… Firefox 140.0+ Fix from $1,6002025-06-24 CRITICAL 9.8 CVE-2025-6424 A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox… Firefox 115.25.0 / 128.12.0+ Fix from $2,3002025-06-24 CRITICAL 9.1 CVE-2025-6427 An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the… Firefox 140.0+ Fix from $2,3002025-06-24 HIGH 8.8 CVE-2025-6426 The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other v… Firefox 128.12.0 / 140.0+ Fix from $1,9502025-06-24 MEDIUM 6.5 CVE-2025-6429 Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could … Firefox 128.12.0 / 140.0+ Fix from $1,6002025-06-24 MEDIUM 6.1 CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>… Firefox 128.12.0 / 140.0+ Fix from $1,6002025-06-24 HIGH 7.8 CVE-2025-5687 A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other op… Vpn 2.28.0+ Fix from $1,9502025-06-11 MEDIUM 6.5 CVE-2025-5986 A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory witho… Thunderbird 128.11.1 / 139.0.2+ Fix from $1,6002025-06-11 CRITICAL 9.8 CVE-2025-49710 An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4. Firefox 139.0.4+ Fix from $2,3002025-06-11 CRITICAL 9.8 CVE-2025-49709 Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. Firefox 139.0.4+ Fix from $2,3002025-06-11 HIGH 7.3 CVE-2025-5272 Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 139.0+ Fix from $1,9502025-05-27 HIGH 8.1 CVE-2025-5268 Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory … Firefox 128.11.0 / 139.0+ Fix from $1,9502025-05-27 HIGH 8.1 CVE-2025-5269 Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enoug… Firefox 128.11.0+ Fix from $1,9502025-05-27 HIGH 7.5 CVE-2025-5270 In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbi… Firefox 139.0+ Fix from $1,9502025-05-27 MEDIUM 6.5 CVE-2025-5271 Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 13… Firefox 139.0+ Fix from $1,6002025-05-27 MEDIUM 5.4 CVE-2025-5267 A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was… Firefox 128.11.0 / 139.0+ Fix from $1,6002025-05-27 HIGH 7.5 CVE-2025-5262 A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have c… Thunderbird 128.11.0 / 139.0+ Fix from $1,9502025-05-27 CRITICAL 9.8 CVE-2025-4918EPSS 9% An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fir… Firefox 115.23.1 / 128.10.1+ Fix from $2,3002025-05-17 HIGH 8.8 CVE-2025-4919EPSS 9% An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in… Firefox 115.23.1 / 128.10.1+ Fix from $1,9502025-05-17 HIGH 8.1 CVE-2025-3909 Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a … Thunderbird 128.10.1 / 138.0.1+ Fix from $1,9502025-05-14