CVE-2025-10532
- EPSS 0.06%
- Veröffentlicht 16.09.2025 12:26:36
- Zuletzt bearbeitet 03.11.2025 19:15:45
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10536
- EPSS 0.02%
- Veröffentlicht 16.09.2025 12:26:36
- Zuletzt bearbeitet 03.11.2025 19:15:45
Information disclosure in the Networking: Cache component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10527
- EPSS 0.05%
- Veröffentlicht 16.09.2025 12:26:35
- Zuletzt bearbeitet 03.11.2025 19:15:44
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10528
- EPSS 0.08%
- Veröffentlicht 16.09.2025 12:26:35
- Zuletzt bearbeitet 03.11.2025 19:15:44
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10529
- EPSS 0.06%
- Veröffentlicht 16.09.2025 12:26:35
- Zuletzt bearbeitet 03.11.2025 19:15:45
Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10533
- EPSS 0.08%
- Veröffentlicht 16.09.2025 12:26:34
- Zuletzt bearbeitet 03.11.2025 19:15:45
Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-55029
- EPSS 0.11%
- Veröffentlicht 19.08.2025 20:52:50
- Zuletzt bearbeitet 21.08.2025 18:39:13
Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks This vulnerability affects Firefox for iOS < 142.
CVE-2025-55028
- EPSS 0.07%
- Veröffentlicht 19.08.2025 20:52:49
- Zuletzt bearbeitet 21.08.2025 18:39:22
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142.
CVE-2025-55031
- EPSS 0.09%
- Veröffentlicht 19.08.2025 20:52:49
- Zuletzt bearbeitet 21.08.2025 18:38:56
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into t...
CVE-2025-54145
- EPSS 0.05%
- Veröffentlicht 19.08.2025 20:52:48
- Zuletzt bearbeitet 21.08.2025 18:39:33
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141.