Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-1942 When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vuln… Firefox 136.0+ Fix from $2,3002025-03-04 CRITICAL 9.1 CVE-2025-1941 Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE… Firefox 136.0+ Fix from $2,3002025-03-04 HIGH 8.2 CVE-2025-1943 Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 136.0+ Fix from $1,9502025-03-04 MEDIUM 5.4 CVE-2025-27426 Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in … Firefox 136.0+ Fix from $1,6002025-03-04 HIGH 8.1 CVE-2025-1932 An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and la… Firefox 128.8.0 / 136.0+ Fix from $1,9502025-03-04 HIGH 7.6 CVE-2025-1933 On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treat… Firefox 115.21.0 / 128.8+ Fix from $1,9502025-03-04 HIGH 7.5 CVE-2025-1937 Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed e… Firefox 115.21.0 / 128.8.0+ Fix from $1,9502025-03-04 HIGH 7.3 CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the ar… Firefox 128.8.0 / 136.0+ Fix from $1,9502025-03-04 HIGH 7.1 CVE-2025-1940 A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launch… Firefox 136.0+ Fix from $1,9502025-03-04 MEDIUM 6.5 CVE-2025-1934 It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the eng… Firefox 128.8.0 / 136.0+ Fix from $1,6002025-03-04 MEDIUM 6.5 CVE-2025-1938 Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory co… Firefox 128.7.0 / 135.0+ Fix from $1,6002025-03-04 HIGH 8.8 CVE-2025-1930 On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could … Firefox 115.21.0 / 128.8+ Fix from $1,9502025-03-04 HIGH 7.5 CVE-2025-1931 It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This … Firefox 115.21.0 / 128.8.0+ Fix from $1,9502025-03-04 MEDIUM 6.5 CVE-2025-1414 Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 135.0.1+ Fix from $1,6002025-02-18 CRITICAL 9.8 CVE-2025-1016 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of… Firefox 115.20.0 / 128.7.0+ Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2025-1017 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory co… Firefox 128.7.0 / 135.0+ Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2025-1020 Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 135.0+ Fix from $2,3002025-02-04 HIGH 8.8 CVE-2025-1014 Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fi… Firefox 128.7.0 / 135.0+ Fix from $1,9502025-02-04 HIGH 7.5 CVE-2025-1012 A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox … Firefox 115.20.0 / 128.7.0+ Fix from $1,9502025-02-04 MEDIUM 6.5 CVE-2025-1013 A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy lea… Firefox 128.7.0 / 135.0+ Fix from $1,6002025-02-04 MEDIUM 5.4 CVE-2025-1015 The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containin… Thunderbird 128.7.0+ Fix from $1,6002025-02-04 MEDIUM 5.3 CVE-2025-1018 The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a po… Firefox 135.0+ Fix from $1,6002025-02-04 CRITICAL 9.8 CVE-2025-1009 An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir… Firefox 115.20.0 / 128.7.0+ Fix from $2,3002025-02-04 HIGH 8.8 CVE-2025-1010 An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed… Firefox 115.20.0 / 128.7.0+ Fix from $1,9502025-02-04 HIGH 8.8 CVE-2025-1011 A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution… Firefox 128.7.0 / 135.0+ Fix from $1,9502025-02-04 MEDIUM 6.5 CVE-2025-0510 Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-4904… Thunderbird 128.7.0 / 135.0+ Fix from $1,6002025-02-04 MEDIUM 6.5 CVE-2025-23109 Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Fir… Firefox 134.0+ Fix from $1,6002025-01-11 CRITICAL 9.8 CVE-2025-0247EPSS 9% Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 134.0+ Fix from $2,3002025-01-07 MEDIUM 6.5 CVE-2025-0246 When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other ope… Firefox 134.0+ Fix from $1,6002025-01-07 MEDIUM 5.3 CVE-2025-0244EPSS 7% When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. … Firefox 134.0+ Fix from $1,6002025-01-07