CVE-2025-10530
- EPSS 0.04%
- Veröffentlicht 16.09.2025 12:26:37
- Zuletzt bearbeitet 30.10.2025 17:15:34
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox < 143 and Thunderbird < 143.
CVE-2025-10537
- EPSS 0.05%
- Veröffentlicht 16.09.2025 12:26:37
- Zuletzt bearbeitet 03.11.2025 19:15:45
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arb...
CVE-2025-10532
- EPSS 0.05%
- Veröffentlicht 16.09.2025 12:26:36
- Zuletzt bearbeitet 03.11.2025 19:15:45
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10536
- EPSS 0.02%
- Veröffentlicht 16.09.2025 12:26:36
- Zuletzt bearbeitet 03.11.2025 19:15:45
Information disclosure in the Networking: Cache component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10527
- EPSS 0.06%
- Veröffentlicht 16.09.2025 12:26:35
- Zuletzt bearbeitet 03.11.2025 19:15:44
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10528
- EPSS 0.1%
- Veröffentlicht 16.09.2025 12:26:35
- Zuletzt bearbeitet 03.11.2025 19:15:44
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10529
- EPSS 0.05%
- Veröffentlicht 16.09.2025 12:26:35
- Zuletzt bearbeitet 03.11.2025 19:15:45
Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-10533
- EPSS 0.07%
- Veröffentlicht 16.09.2025 12:26:34
- Zuletzt bearbeitet 03.11.2025 19:15:45
Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
CVE-2025-55029
- EPSS 0.06%
- Veröffentlicht 19.08.2025 20:52:50
- Zuletzt bearbeitet 21.08.2025 18:39:13
Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks This vulnerability affects Firefox for iOS < 142.
CVE-2025-55028
- EPSS 0.05%
- Veröffentlicht 19.08.2025 20:52:49
- Zuletzt bearbeitet 21.08.2025 18:39:22
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142.