Show filters
2,812 Total Results
Displaying 21-30 of 2,812
Sort by:
Attacker Value
Unknown

CVE-2025-1012

Disclosure Date: February 04, 2025 (last updated February 07, 2025)
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Attacker Value
Unknown

CVE-2025-1011

Disclosure Date: February 04, 2025 (last updated February 07, 2025)
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Attacker Value
Unknown

CVE-2025-1010

Disclosure Date: February 04, 2025 (last updated February 07, 2025)
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Attacker Value
Unknown

CVE-2025-1009

Disclosure Date: February 04, 2025 (last updated February 07, 2025)
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Attacker Value
Unknown

CVE-2025-23109

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.
0
Attacker Value
Unknown

CVE-2025-23108

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
0
Attacker Value
Unknown

CVE-2025-0247

Disclosure Date: January 07, 2025 (last updated January 13, 2025)
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Thunderbird < 134.
0
Attacker Value
Unknown

CVE-2025-0246

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.
0
Attacker Value
Unknown

CVE-2025-0245

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.
0
Attacker Value
Unknown

CVE-2025-0244

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134.
0