VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,368)

  • CVE-2025-5268HigMay 27, 2025
    risk 0.53cvss 8.1epss 0.00

    Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This…

  • CVE-2025-4093HigApr 29, 2025
    risk 0.53cvss 8.1epss 0.00

    Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.10 and Thunderbird…

  • CVE-2025-4091HigApr 29, 2025
    risk 0.53cvss 8.1epss 0.00

    Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability…

  • CVE-2025-3034HigApr 1, 2025
    risk 0.53cvss 8.1epss 0.00

    Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 137 and…

  • CVE-2025-3030HigApr 1, 2025
    risk 0.53cvss 8.1epss 0.01

    Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability…

  • CVE-2025-1943HigMar 4, 2025
    risk 0.53cvss 8.2epss 0.00

    Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136 and…

  • CVE-2025-1932HigMar 4, 2025
    risk 0.53cvss 8.1epss 0.00

    An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

  • CVE-2024-11700HigNov 26, 2024
    risk 0.53cvss 8.1epss 0.00

    Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133…

  • CVE-2024-7525HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.01

    It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and…

  • CVE-2024-7523HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.00

    A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

  • CVE-2024-6606HigJul 9, 2024
    risk 0.53cvss 8.2epss 0.00

    Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.

  • CVE-2024-5688HigJun 11, 2024
    risk 0.53cvss 8.1epss 0.01

    If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

  • CVE-2024-4776HigMay 14, 2024
    risk 0.53cvss 8.2epss 0.00

    A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

  • CVE-2024-4765HigMay 14, 2024
    risk 0.53cvss 8.1epss 0.00

    Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for…

  • CVE-2024-3865HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.00

    Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.

  • CVE-2024-3864HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.01

    Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR <…

  • CVE-2024-2612HigMar 19, 2024
    risk 0.53cvss 8.1epss 0.01

    If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2024-2607HigMar 19, 2024
    risk 0.53cvss 8.1epss 0.01

    Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2024-1557HigFeb 20, 2024
    risk 0.53cvss 8.1epss 0.01

    Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123.

  • CVE-2024-1553HigFeb 20, 2024
    risk 0.53cvss 8.1epss 0.01

    Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

Page 48 of 169