|
2411
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Firefox para Android permitía un iframe de la sandbox sin el atributo `allow-downloads` para iniciar descargas. Esta vulnerabilidad afecta a Firefox anterior a la versión 141.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-8042
|
2026-04-14 00:17 |
2025-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2412
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in Firefox 141.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2025-8041
|
2026-04-14 00:17 |
2025-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2413
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
En la barra de direcciones, Firefox para Android truncaba la visualización de las URL desde el final en lugar de priorizar el origen. Esta vulnerabilidad afecta a Firefox anterior a la versión 141.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2025-8041
|
2026-04-14 00:17 |
2025-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2414
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8040
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2415
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 y Thunderbird 140. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8040
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2416
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 1…
|
CWE-200
Information Exposure
|
CVE-2025-8039
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2417
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
En algunos casos, los términos de búsqueda persistían en la barra de URL incluso después de salir de la página de búsqueda. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 140.1, Thun…
|
CWE-200
Information Exposure
|
CVE-2025-8039
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2418
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-8038
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2419
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird ignoraba las rutas al comprobar la validez de las navegaciones en un frame. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141 y Thunderbird < …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-8038
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2420
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerab…
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2025-8037
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|