Vulnerabilities > Mozilla > Firefox > 91.6.1

DATE CVE VULNERABILITY TITLE RISK
2025-02-04 CVE-2025-1009 Use After Free vulnerability in Mozilla Firefox
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
critical
9.8
2025-02-04 CVE-2025-1010 Use After Free vulnerability in Mozilla Firefox
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
8.8
2025-02-04 CVE-2025-1011 Unspecified vulnerability in Mozilla Firefox
A bug in WebAssembly code generation could have lead to a crash.
network
low complexity
mozilla
8.8
2025-02-04 CVE-2025-1012 Use After Free vulnerability in Mozilla Firefox
A race during concurrent delazification could have led to a use-after-free.
network
high complexity
mozilla CWE-416
7.5
2025-02-04 CVE-2025-1014 Improper Certificate Validation vulnerability in Mozilla Firefox
Certificate length was not properly checked when added to a certificate store.
network
low complexity
mozilla CWE-295
8.8
2025-02-04 CVE-2025-1016 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6.
network
low complexity
mozilla CWE-787
critical
9.8
2025-02-04 CVE-2025-1017 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6.
network
low complexity
mozilla CWE-787
critical
9.8
2024-11-06 CVE-2024-10941 Unspecified vulnerability in Mozilla Firefox
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.
network
low complexity
mozilla
6.5
2024-10-29 CVE-2024-10458 Unspecified vulnerability in Mozilla Thunderbird
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements.
network
low complexity
mozilla
7.5
2024-10-29 CVE-2024-10459 Use After Free vulnerability in Mozilla Thunderbird
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
7.5