Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2025-11721

4 месяца назад

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11720

4 месяца назад

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-11720

4 месяца назад

The Firefox and Firefox Focus UI for the Android custom tab feature on ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-11719

4 месяца назад

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11719

4 месяца назад

Starting in Thunderbird 143, the use of the native messaging API by we ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11718

4 месяца назад

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-11718

4 месяца назад

When the address bar was hidden due to scrolling on Android, a malicio ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-11717

4 месяца назад

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability affects Firefox < 144.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2025-11717

4 месяца назад

When switching between Android apps using the card carousel Firefox sh ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2025-11716

4 месяца назад

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-11721

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11720

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11720

The Firefox and Firefox Focus UI for the Android custom tab feature on ...

CVSS3: 8.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by we ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11718

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

CVSS3: 6.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11718

When the address bar was hidden due to scrolling on Android, a malicio ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11717

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability affects Firefox < 144.

CVSS3: 9.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11717

When switching between Android apps using the card carousel Firefox sh ...

CVSS3: 9.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11716

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 6.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться