CVE-2025-13021
- EPSS 0.08%
- Veröffentlicht 11.11.2025 15:47:13
- Zuletzt bearbeitet 19.11.2025 20:15:51
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
CVE-2025-13022
- EPSS 0.08%
- Veröffentlicht 11.11.2025 15:47:13
- Zuletzt bearbeitet 19.11.2025 20:15:51
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
CVE-2025-13023
- EPSS 0.08%
- Veröffentlicht 11.11.2025 15:47:13
- Zuletzt bearbeitet 19.11.2025 20:15:51
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
CVE-2025-13014
- EPSS 0.1%
- Veröffentlicht 11.11.2025 15:47:12
- Zuletzt bearbeitet 19.11.2025 20:15:49
Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
CVE-2025-13015
- EPSS 0.1%
- Veröffentlicht 11.11.2025 15:47:12
- Zuletzt bearbeitet 19.11.2025 20:15:49
Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
CVE-2025-13012
- EPSS 0.07%
- Veröffentlicht 11.11.2025 15:47:11
- Zuletzt bearbeitet 19.11.2025 20:15:49
Race condition in the Graphics component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
CVE-2025-13013
- EPSS 0.09%
- Veröffentlicht 11.11.2025 15:47:11
- Zuletzt bearbeitet 19.11.2025 20:15:49
Mitigation bypass in the DOM: Core & HTML component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
CVE-2025-12380
- EPSS 0.08%
- Veröffentlicht 28.10.2025 14:06:34
- Zuletzt bearbeitet 19.12.2025 18:00:35
Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have been usable to escape the child process sandbox. This vulnerability aff...
CVE-2025-11720
- EPSS 0.04%
- Veröffentlicht 14.10.2025 12:27:38
- Zuletzt bearbeitet 15.10.2025 18:10:00
The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content ...
CVE-2025-11717
- EPSS 0.04%
- Veröffentlicht 14.10.2025 12:27:37
- Zuletzt bearbeitet 15.10.2025 18:13:39
When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability affec...