Логотип exploitDog
source:"redhat"
Консоль
Логотип exploitDog

exploitDog

source:"redhat"

Количество 41 119

Количество 41 119

redhat логотип

CVE-2025-10536

4 месяца назад

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 3.4
EPSS: Низкий
redhat логотип

CVE-2025-10535

4 месяца назад

This vulnerability affects Firefox < 143.

CVSS3: 3.4
EPSS: Низкий
redhat логотип

CVE-2025-10534

4 месяца назад

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVSS3: 3.4
EPSS: Низкий
redhat логотип

CVE-2025-10533

4 месяца назад

This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-10532

4 месяца назад

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-10531

4 месяца назад

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-10530

4 месяца назад

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-10529

4 месяца назад

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-10528

4 месяца назад

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-10527

4 месяца назад

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-10256

больше 1 года назад

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-1020

11 месяцев назад

Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135 and Thunderbird < 135.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-1019

11 месяцев назад

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2025-1018

11 месяцев назад

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2025-1017

11 месяцев назад

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-1016

11 месяцев назад

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-1015

11 месяцев назад

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.

CVSS3: 5.4
EPSS: Средний
redhat логотип

CVE-2025-1014

11 месяцев назад

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-10148

4 месяца назад

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2025-1013

11 месяцев назад

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-10536

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 3.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10535

This vulnerability affects Firefox < 143.

CVSS3: 3.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10534

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVSS3: 3.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10533

This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10532

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10531

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10530

This vulnerability affects Firefox < 143 and Thunderbird < 143.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10529

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10528

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10527

This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-10256

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.

CVSS3: 5.3
больше 1 года назад
redhat логотип
CVE-2025-1020

Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135 and Thunderbird < 135.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-1019

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-1018

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-1017

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-1016

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-1015

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.

CVSS3: 5.4
29%
Средний
11 месяцев назад
redhat логотип
CVE-2025-1014

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-10148

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

CVSS3: 4.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-1013

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 4.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу