Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 29.04.2025 13:13:38
  • Last modified 09.05.2025 19:33:28

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows...

  • EPSS 0.05%
  • Published 29.04.2025 13:13:36
  • Last modified 09.05.2025 19:33:33

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This v...

  • EPSS 0.04%
  • Published 29.04.2025 13:13:35
  • Last modified 09.05.2025 19:33:39

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird ar...

  • EPSS 0.07%
  • Published 29.04.2025 13:13:33
  • Last modified 13.06.2025 18:53:56

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access ...

  • EPSS 0.02%
  • Published 15.04.2025 12:57:28
  • Last modified 21.05.2025 19:48:33

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.

Exploit
  • EPSS 0.16%
  • Published 01.04.2025 13:15:41
  • Last modified 07.04.2025 13:31:38

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

  • EPSS 0.1%
  • Published 01.04.2025 13:15:41
  • Last modified 07.04.2025 13:31:33

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

  • EPSS 0.06%
  • Published 01.04.2025 13:15:41
  • Last modified 07.04.2025 13:31:26

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitr...

  • EPSS 0.04%
  • Published 01.04.2025 13:15:41
  • Last modified 07.04.2025 13:31:10

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.

  • EPSS 0.03%
  • Published 01.04.2025 13:15:41
  • Last modified 07.04.2025 13:31:04

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.