Where
-Infinity
0

Mozilla FirefoxSecurity Vulnerabilities fixed in Firefox 139.0.4

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-47

Mozilla FirefoxMemory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxDue to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker cou…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxError handling for script execution was incorrectly isolated from web content, which could have allo…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxScript elements loading cross-origin resources generated load and error events which leaked informat…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla FirefoxA clickjacking vulnerability could have been used to trick a user into leaking saved payment card de…

Risk 5
Severity
1
First published (updated )

Mozilla ThunderbirdDouble Free

Risk 43
Severity
7.5
First published (updated )

Mozilla Firefox ESRA double-free could have occurred in vpx_codec_enc_init_multi after a failed allocation when initial…

Risk 42
Severity
9
First published (updated )

Mozilla FirefoxZDI-25-291: (Pwn2Own) Mozilla Firefox IonMonkey JIT Compiler Integer Overflow Remote Code Execution Vulnerability

Risk 61
First published (updated )

Mozilla Firefox(Pwn2Own) Mozilla Firefox IonMonkey JIT Compiler Integer Overflow Remote Code Execution Vulnerability

Risk 67
First published (updated )
Advisory
ZDI-25-291
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla FirefoxSecurity Vulnerabilities fixed in Firefox for iOS 139

Risk 5
Severity
1
First published (updated )
Advisory
MFSA2025-39

BleepingComputerMozilla fixes Firefox zero-days exploited at hacking contest

First published (updated )

BleepingComputerHackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin

First published (updated )

Mozilla Firefox2 vulnerabilities

Risk 42
Severity
9
First published (updated )
Advisory
MFSA2025-36

Rejected reason: Duplicate of CVE-2025-4918

Risk 36
Severity
9
EPSS
0.02%
First published (updated )

Rejected reason: Duplicate of CVE-2025-4919

Risk 36
Severity
9
EPSS
0.02%
First published (updated )

ZDNetYour password manager is under attack: How to defend yourself against a new threat

First published (updated )
News
ZDNet
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdMozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYS…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdMemory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9…

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdA process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdA vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due t…

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdMemory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdModification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when ch…

Risk 33
Severity
7
First published (updated )

Mozilla FirefoxA security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed re…

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdA vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due t…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxDue to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could …

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdAn attacker with control over a content process could potentially leverage the privileged UITour act…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdMemory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdA vulnerability existed in Firefox for Android where potentially sensitive library locations were lo…

Risk 5
Severity
1
First published (updated )

Mozilla ThunderbirdA process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203