CVE-2025-8031
- EPSS 0.15%
- Veröffentlicht 22.07.2025 20:49:26
- Zuletzt bearbeitet 15.08.2025 14:25:03
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunde...
CVE-2025-8032
- EPSS 0.07%
- Veröffentlicht 22.07.2025 20:49:26
- Zuletzt bearbeitet 28.07.2025 18:40:44
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
CVE-2025-8038
- EPSS 0.03%
- Veröffentlicht 22.07.2025 20:49:26
- Zuletzt bearbeitet 29.09.2025 23:03:01
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
CVE-2025-8030
- EPSS 0.05%
- Veröffentlicht 22.07.2025 20:49:25
- Zuletzt bearbeitet 28.07.2025 18:38:03
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13...
CVE-2025-8036
- EPSS 0.05%
- Veröffentlicht 22.07.2025 20:49:25
- Zuletzt bearbeitet 29.09.2025 23:02:08
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
CVE-2025-8037
- EPSS 0.02%
- Veröffentlicht 22.07.2025 20:49:25
- Zuletzt bearbeitet 28.07.2025 18:51:21
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, T...
CVE-2025-8027
- EPSS 0.05%
- Veröffentlicht 22.07.2025 20:49:24
- Zuletzt bearbeitet 28.07.2025 18:30:57
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 14...
CVE-2025-8028
- EPSS 0.07%
- Veröffentlicht 22.07.2025 20:49:24
- Zuletzt bearbeitet 28.07.2025 18:32:21
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.2...
CVE-2025-8029
- EPSS 0.05%
- Veröffentlicht 22.07.2025 20:49:24
- Zuletzt bearbeitet 29.09.2025 23:00:54
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
CVE-2025-3467
- EPSS 0.04%
- Veröffentlicht 07.07.2025 09:56:19
- Zuletzt bearbeitet 10.07.2025 13:34:32
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administra...