Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2025-11711

4 месяца назад

There was a way to change the value of JavaScript Object properties th ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-11710

4 месяца назад

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11710

4 месяца назад

A compromised web process using malicious IPC messages could have caus ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11709

4 месяца назад

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11709

4 месяца назад

A compromised web process was able to trigger out of bounds reads and ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11708

4 месяца назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11708

4 месяца назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerabilit ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11720

4 месяца назад

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2025-11717

4 месяца назад

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability affects Firefox < 144.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2025-11709

4 месяца назад

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-11711

There was a way to change the value of JavaScript Object properties th ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11710

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11710

A compromised web process using malicious IPC messages could have caus ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerabilit ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11720

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11717

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability affects Firefox < 144.

CVSS3: 9.1
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться