Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2025-11711

4 месяца назад

There was a way to change the value of JavaScript Object properties th ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-11710

4 месяца назад

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11710

4 месяца назад

A compromised web process using malicious IPC messages could have caus ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11709

4 месяца назад

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11709

4 месяца назад

A compromised web process was able to trigger out of bounds reads and ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11708

4 месяца назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11708

4 месяца назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerabilit ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11718

4 месяца назад

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-11719

4 месяца назад

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11708

4 месяца назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-11711

There was a way to change the value of JavaScript Object properties th ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11710

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11710

A compromised web process using malicious IPC messages could have caus ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerabilit ...

CVSS3: 9.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11718

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

CVSS3: 6.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 9.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться