CVE-2025-11710
- EPSS 0.08%
- Veröffentlicht 14.10.2025 12:27:34
- Zuletzt bearbeitet 03.11.2025 18:15:47
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Th...
CVE-2025-11711
- EPSS 0.03%
- Veröffentlicht 14.10.2025 12:27:34
- Zuletzt bearbeitet 03.11.2025 18:15:48
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
CVE-2025-11714
- EPSS 0.05%
- Veröffentlicht 14.10.2025 12:27:34
- Zuletzt bearbeitet 03.11.2025 18:15:48
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been ...
CVE-2025-11709
- EPSS 0.08%
- Veröffentlicht 14.10.2025 12:27:33
- Zuletzt bearbeitet 03.11.2025 18:15:47
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Th...
- EPSS 0.02%
- Veröffentlicht 30.09.2025 13:15:48
- Zuletzt bearbeitet 03.10.2025 20:16:14
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS ...
CVE-2025-11152
- EPSS 0.05%
- Veröffentlicht 30.09.2025 13:15:48
- Zuletzt bearbeitet 30.10.2025 17:15:36
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143.0.3.
CVE-2025-11153
- EPSS 0.04%
- Veröffentlicht 30.09.2025 13:15:48
- Zuletzt bearbeitet 13.10.2025 11:15:40
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 143.0.3.
CVE-2025-10531
- EPSS 0.04%
- Veröffentlicht 16.09.2025 12:26:38
- Zuletzt bearbeitet 30.10.2025 17:15:35
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability affects Firefox < 143 and Thunderbird < 143.
CVE-2025-10534
- EPSS 0.05%
- Veröffentlicht 16.09.2025 12:26:38
- Zuletzt bearbeitet 30.10.2025 17:15:35
Spoofing issue in the Site Permissions component. This vulnerability affects Firefox < 143 and Thunderbird < 143.
CVE-2025-10535
- EPSS 0.05%
- Veröffentlicht 16.09.2025 12:26:38
- Zuletzt bearbeitet 30.10.2025 17:15:35
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability affects Firefox < 143.