|
2431
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
La carga de documentos XSLT no propagó correctamente el documento fuente, lo que eludió su CSP. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunder…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-8032
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2432
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 12…
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-8031
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2433
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
La parte `username:password` no se eliminó correctamente de las URL en los informes de CSP, lo que podría filtrar credenciales de autenticación básica HTTP. Esta vulnerabilidad afecta a Firefox < …
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-8031
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2434
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox …
|
CWE-94
Code Injection
|
CVE-2025-8030
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2435
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Un escape insuficiente en la función "Copiar como cURL" podría utilizarse para engañar al usuario y que ejecute código inesperado. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.…
|
CWE-94
Code Injection
|
CVE-2025-8030
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2436
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13…
|
CWE-80
Basic XSS
|
CVE-2025-8029
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2437
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird ejecutaba URLs `javascript:` al usarlas en las etiquetas `object` e `embed`. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird &l…
|
CWE-80
Basic XSS
|
CVE-2025-8029
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2438
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulne…
|
CWE-1332
Improper Handling of Faults that Lead to Instruction Skips
|
CVE-2025-8028
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2439
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
En arm64, una instrucción WASM `br_table` con muchas entradas podría provocar que la etiqueta se alejara demasiado de la instrucción, lo que causaría truncamiento y un cálculo incorrecto de la direcc…
|
CWE-1332
Improper Handling of Faults that Lead to Instruction Skips
|
CVE-2025-8028
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2440
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefo…
|
CWE-457
Use of Uninitialized Variable
|
CVE-2025-8027
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|