Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

nvd логотип

CVE-2025-0240

10 месяцев назад

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2025-0240

10 месяцев назад

Parsing a JavaScript module as JSON could, under some circumstances, c ...

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2025-0239

10 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2025-0239

10 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when t ...

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2025-0238

10 месяцев назад

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-0238

10 месяцев назад

Assuming a controlled failed memory allocation, an attacker could have ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-0237

10 месяцев назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-0237

10 месяцев назад

The WebChannel API, which is used to transport various information acr ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-0237

10 месяцев назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-0240

10 месяцев назад

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-0240

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-0240

Parsing a JavaScript module as JSON could, under some circumstances, c ...

CVSS3: 4
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when t ...

CVSS3: 4
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-0238

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-0238

Assuming a controlled failed memory allocation, an attacker could have ...

CVSS3: 5.3
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information acr ...

CVSS3: 5.4
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-0240

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
0%
Низкий
10 месяцев назад

Уязвимостей на страницу


Поделиться