Where
-Infinity
0

Mozilla Firefox ESRMemory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxMemory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxDue to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker cou…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxError handling for script execution was incorrectly isolated from web content, which could have allo…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxScript elements loading cross-origin resources generated load and error events which leaked informat…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla FirefoxA clickjacking vulnerability could have been used to trick a user into leaking saved payment card de…

Risk 5
Severity
1
First published (updated )

Mozilla ThunderbirdDouble Free

Risk 43
Severity
7.5
First published (updated )

Mozilla Firefox ESRA double-free could have occurred in vpx_codec_enc_init_multi after a failed allocation when initial…

Risk 42
Severity
9
First published (updated )

BleepingComputerMozilla fixes Firefox zero-days exploited at hacking contest

First published (updated )

BleepingComputerHackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla Firefox ESRAn attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. Thi…

Risk 33
Severity
7
First published (updated )

Mozilla Firefox ESRAn attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing a…

Risk 33
Severity
7
First published (updated )

Mozilla Firefox ESRSecurity Vulnerabilities fixed in Firefox ESR 115.23.1

Risk 42
Severity
9
First published (updated )
Advisory
MFSA2025-38

Mozilla Firefox ESR2 vulnerabilities

Risk 42
Severity
9
First published (updated )
Advisory
MFSA2025-37

Rejected reason: Duplicate of CVE-2025-4918

Risk 36
Severity
9
EPSS
0.02%
First published (updated )

Rejected reason: Duplicate of CVE-2025-4919

Risk 36
Severity
9
EPSS
0.02%
First published (updated )

Mozilla ThunderbirdMozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYS…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdMemory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9…

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdA process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )

Mozilla Firefox ESRMemory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of m…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdA vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due t…

Risk 19
Severity
4
First published (updated )

Mozilla Firefox ESR6 vulnerabilities

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-29

Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9…

Risk 19
Severity
4
First published (updated )

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when ch…

Risk 33
Severity
7
First published (updated )

A vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due t…

Risk 19
Severity
4
First published (updated )

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker co…

Risk 19
Severity
4
First published (updated )

Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of m…

Risk 33
Severity
7
First published (updated )

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla Firefox ESR3 vulnerabilities

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-30

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when ch…

Risk 33
Severity
7
First published (updated )

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker co…

Risk 19
Severity
4
First published (updated )

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdMemory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8…

Risk 33
Severity
7
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203