mozilla

3,564 tracked vulnerabilities.

CVE-2025-10532 MEDIUM
Firefox < 143.0 and 140.3-140.* - Memory Corruption in JavaScript GC
Sep 16, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10531 MEDIUM
Firefox <143 - Privilege Escalation
Sep 16, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-10530 MEDIUM
Firefox for Android < 143.0 - Authentication Bypass by Spoofing in WebAuthn Component
Sep 16, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10529 MEDIUM
Firefox < 140.3.0 and 140.3-140.* - Same-Origin Policy Bypass in Layout Component
Sep 16, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10528 HIGH
Firefox < 143.0 and 140.3-140.* - Sandbox Escape via Canvas2D Invalid Pointer
Sep 16, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-10527 HIGH
Firefox < 143.0 and 140.3-140.* - Use-After-Free in Graphics Canvas2D
Sep 16, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-10290 MEDIUM
Mozilla Focus for iOS < 143.0 - User Interface Misrepresentation via Contextual Menu URL Spoofing
Sep 16, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-9187 CRITICAL
Firefox < 142.0 and Thunderbird < 142.0 - Memory Corruption
Aug 19, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-9186 MEDIUM
Firefox < 142.0 - Address Bar Spoofing
Aug 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-9185 HIGH
Firefox < 115.27.0, 115.27-115.*, < 128.14, 128.14-128.*, < 140.2, 140.2-140.*, >=142 - Memory Corruption
Aug 19, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-9184 HIGH
Firefox <142 - Firefox ESR <140.2 - Memory Corruption
Aug 19, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-9183 MEDIUM
Firefox < 142.0 and 140.2-140.* - Address Bar Spoofing
Aug 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-9182 HIGH
Firefox < 142.0 and 140.2-140.* - Denial of Service in WebRender Graphics Component
Aug 19, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-9181 MEDIUM
Firefox and Thunderbird - Use of Uninitialized Variable in JavaScript Engine
Aug 19, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-9180 HIGH
Firefox and Thunderbird - Same-Origin Policy Bypass in Canvas2D
Aug 19, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-9179 CRITICAL
Firefox < 115.27.0, < 142.0 and Thunderbird < 128.14.0, < 142.0 - Memory Corruption in GMP Process
Aug 19, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-8364 MEDIUM
Firefox < 141.0 - URL Spoofing via Blob URI
Aug 19, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-8042 CRITICAL
Firefox for Android < 141.0 - Unauthenticated Download Restriction Bypass via Sandboxed Iframe
Aug 19, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-8041 MEDIUM
Firefox < 141.0 - URL Origin Misrepresentation in Address Bar
Aug 19, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-55033 MEDIUM
Mozilla Focus for iOS < 142 - Cross-Site Scripting via URL Bar Drag
Aug 19, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-55032 MEDIUM
Mozilla Focus for iOS < 142 - Cross-Site Scripting via Content-Disposition Header Mishandling
Aug 19, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-55031 CRITICAL
Firefox for iOS < 142 - Open Redirect via FIDO Passkey Transport
Aug 19, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-55030 MEDIUM
Firefox for iOS < 142 - Cross-Site Scripting via Content-Disposition Header Bypass
Aug 19, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-55029 HIGH
Firefox < 142.0 - Denial of Service via Popup Blocker Bypass
Aug 19, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-55028 MEDIUM
Firefox < 142.0 - Denial of Service via Repetitive JavaScript Alerts
Aug 19, 2025
CVSS 6.5
EPSS 0.00