Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 046

debian логотип

CVE-2025-11710

20 дней назад

A compromised web process using malicious IPC messages could have caus ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11709

20 дней назад

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11709

20 дней назад

A compromised web process was able to trigger out of bounds reads and ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-11708

20 дней назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-11708

20 дней назад

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerabilit ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11719

20 дней назад

Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11712

20 дней назад

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2025-11709

20 дней назад

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11716

20 дней назад

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-11713

20 дней назад

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect Firefox running on other operating systems. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-11710

A compromised web process using malicious IPC messages could have caus ...

CVSS3: 9.8
0%
Низкий
20 дней назад
nvd логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
20 дней назад
debian логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and ...

CVSS3: 9.8
0%
Низкий
20 дней назад
nvd логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
20 дней назад
debian логотип
CVE-2025-11708

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerabilit ...

CVSS3: 9.8
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2025-11719

Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 9.8
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2025-11712

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 6.1
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2025-11709

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2025-11716

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability affects Firefox < 144 and Thunderbird < 144.

CVSS3: 6.5
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2025-11713

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect Firefox running on other operating systems. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 8.1
0%
Низкий
20 дней назад

Уязвимостей на страницу


Поделиться