CVE-2025-14327
- EPSS 0.38%
- Veröffentlicht 09.12.2025 13:38:02
- Zuletzt bearbeitet 07.10.2026 20:10:01
Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.
CVE-2025-14326
- EPSS 0.45%
- Veröffentlicht 09.12.2025 13:38:00
- Zuletzt bearbeitet 07.10.2026 20:10:01
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
CVE-2025-14325
- EPSS 0.33%
- Veröffentlicht 09.12.2025 13:37:58
- Zuletzt bearbeitet 07.10.2026 20:10:01
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14324
- EPSS 0.55%
- Veröffentlicht 09.12.2025 13:37:57
- Zuletzt bearbeitet 07.10.2026 20:10:01
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14323
- EPSS 0.41%
- Veröffentlicht 09.12.2025 13:37:56
- Zuletzt bearbeitet 07.10.2026 20:10:01
Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
- EPSS 0.33%
- Veröffentlicht 09.12.2025 13:37:55
- Zuletzt bearbeitet 07.10.2026 20:10:01
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14321
- EPSS 0.58%
- Veröffentlicht 09.12.2025 13:37:53
- Zuletzt bearbeitet 07.10.2026 20:10:01
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-11721
- EPSS 0.34%
- Veröffentlicht 14.10.2025 12:27:37
- Zuletzt bearbeitet 13.04.2026 15:16:41
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and T...
CVE-2025-11715
- EPSS 0.31%
- Veröffentlicht 14.10.2025 12:27:36
- Zuletzt bearbeitet 13.04.2026 15:16:40
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arb...
CVE-2025-11716
- EPSS 0.22%
- Veröffentlicht 14.10.2025 12:27:36
- Zuletzt bearbeitet 13.04.2026 15:16:40
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.