Vulnerabilities > Mozilla > High

DATE CVE VULNERABILITY TITLE RISK
2025-02-04 CVE-2025-1010 Use After Free vulnerability in Mozilla Firefox
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
8.8
2025-02-04 CVE-2025-1011 Unspecified vulnerability in Mozilla Firefox
A bug in WebAssembly code generation could have lead to a crash.
network
low complexity
mozilla
8.8
2025-02-04 CVE-2025-1012 Use After Free vulnerability in Mozilla Firefox
A race during concurrent delazification could have led to a use-after-free.
network
high complexity
mozilla CWE-416
7.5
2025-02-04 CVE-2025-1014 Improper Certificate Validation vulnerability in Mozilla Firefox
Certificate length was not properly checked when added to a certificate store.
network
low complexity
mozilla CWE-295
8.8
2024-10-29 CVE-2024-10458 Unspecified vulnerability in Mozilla Thunderbird
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements.
network
low complexity
mozilla
7.5
2024-10-29 CVE-2024-10459 Use After Free vulnerability in Mozilla Thunderbird
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
7.5
2024-10-29 CVE-2024-10466 Unspecified vulnerability in Mozilla Thunderbird
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.
network
low complexity
mozilla
7.5
2024-10-29 CVE-2024-10467 Out-of-bounds Write vulnerability in Mozilla Thunderbird
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3.
network
low complexity
mozilla CWE-787
8.8
2024-10-01 CVE-2024-9393 Unspecified vulnerability in Mozilla Firefox
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin.
network
low complexity
mozilla
7.5
2024-10-01 CVE-2024-9394 Unspecified vulnerability in Mozilla Firefox
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin.
network
low complexity
mozilla
7.5