CVE-2025-1020
- EPSS 0.24%
- Published 04.02.2025 14:15:32
- Last modified 06.02.2025 21:15:22
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Fi...
CVE-2025-0510
- EPSS 0.07%
- Published 04.02.2025 14:15:31
- Last modified 06.02.2025 21:15:22
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
CVE-2025-1009
- EPSS 0.36%
- Published 04.02.2025 14:15:31
- Last modified 06.02.2025 19:28:52
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
CVE-2025-1010
- EPSS 0.23%
- Published 04.02.2025 14:15:31
- Last modified 06.02.2025 19:30:13
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
CVE-2025-1011
- EPSS 0.18%
- Published 04.02.2025 14:15:31
- Last modified 06.02.2025 19:31:38
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird...
CVE-2025-0247
- EPSS 0.6%
- Published 07.01.2025 16:15:39
- Last modified 03.04.2025 16:25:30
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Fi...
CVE-2025-0237
- EPSS 0.18%
- Published 07.01.2025 16:15:38
- Last modified 03.04.2025 16:29:29
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Fir...
CVE-2025-0238
- EPSS 0.36%
- Published 07.01.2025 16:15:38
- Last modified 03.04.2025 16:29:37
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and Th...
- EPSS 0.05%
- Published 07.01.2025 16:15:38
- Last modified 03.04.2025 16:29:43
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
- EPSS 0.08%
- Published 07.01.2025 16:15:38
- Last modified 03.04.2025 16:29:54
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.