|
2441
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
En plataformas de 64 bits, IonMonkey-JIT solo escribía 32 bits del espacio de valor de retorno de 64 bits en la pila. Sin embargo, Baseline-JIT leía los 64 bits completos. Esta vulnerabilidad afecta …
|
CWE-457
Use of Uninitialized Variable
|
CVE-2025-8027
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2442
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-6436
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2443
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox 139 y Thunderbird 139. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, algunos de…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-6436
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2444
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the us…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-6435
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2445
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Si un usuario guardó una respuesta desde la pestaña Red en DevTools mediante la opción Guardar como del menú contextual, es posible que el archivo no se haya guardado con la extensión `.download`. Es…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-6435
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2446
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an except…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-6434
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2447
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
La página de excepción de la función Solo HTTPS, que se mostraba al abrir un sitio web mediante HTTP, carecía de un retardo anti-clickjacking, lo que potencialmente permitía a un atacante engañar al …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-6434
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2448
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in vi…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-6433
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2449
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Si un usuario visitaba una página web con un certificado TLS no válido y concedía una excepción, la página web podía generar un desafío de WebAuthN que el usuario debía completar. Esto infringe la es…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-6433
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2450
|
8.6 |
HIGH
Network
|
mozilla
|
firefox
|
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firef…
|
CWE-200
Information Exposure
|
CVE-2025-6432
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|