Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

128129130131132133134135136137138139202420252026

Недавние уязвимости Mozilla Firefox

Количество 14 600

github логотип

GHSA-m2rp-964h-h237

4 месяца назад

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r83v-rmq7-r5m4

4 месяца назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m793-xp46-r76w

4 месяца назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-h267-996p-9gjc

4 месяца назад

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-5289-2q6r-6q3g

4 месяца назад

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-27424

4 месяца назад

Websites redirecting to a non-HTTP scheme URL could allow a website ad ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-27424

4 месяца назад

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-1942

4 месяца назад

When String.toUpperCase() caused a string to get longer it was possibl ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-1942

4 месяца назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-1941

4 месяца назад

Under certain circumstances, a user opt-in setting that Focus should r ...

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-m2rp-964h-h237

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-r83v-rmq7-r5m4

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-m793-xp46-r76w

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.

CVSS3: 9.1
0%
Низкий
4 месяца назад
github логотип
GHSA-h267-996p-9gjc

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-5289-2q6r-6q3g

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.

CVSS3: 8.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-27424

Websites redirecting to a non-HTTP scheme URL could allow a website ad ...

CVSS3: 4.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-27424

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.

CVSS3: 4.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-1942

When String.toUpperCase() caused a string to get longer it was possibl ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-1942

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-1941

Under certain circumstances, a user opt-in setting that Focus should r ...

CVSS3: 9.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться