|
2461
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox
|
Un atacante logró eludir la directiva `connect-src` de una Política de Seguridad de Contenido manipulando subdocumentos. Esto también habría ocultado las conexiones de la pestaña Red en DevTools. Est…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-6427
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2462
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
The executable file warning did not warn users before opening files with the `terminal` extension.
*This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerab…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-6426
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2463
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
La advertencia del archivo ejecutable no avisaba a los usuarios antes de abrir archivos con la extensión `terminal`. *Este error solo afecta a Firefox para macOS. Las demás versiones de Firefox no se…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-6426
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2464
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode,…
|
CWE-200
Information Exposure
|
CVE-2025-6425
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2465
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Un atacante que enumerara recursos desde la extensión WebCompat podría haber obtenido un UUID persistente que identificaba el navegador y persistía entre contenedores y el modo de navegación normal/p…
|
CWE-200
Information Exposure
|
CVE-2025-6425
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2466
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.…
|
CWE-416
Use After Free
|
CVE-2025-6424
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2467
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Use-after-free en FontFaceSet provocó un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Firefox < 140, Firefox ESR < 115.25 y Firefox ESR < 128.12.
|
CWE-416
Use After Free
|
CVE-2025-6424
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2468
|
6.5 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. Thi…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2025-5986
|
2026-04-14 00:17 |
2025-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2469
|
6.5 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
Un correo electrónico HTML manipulado que utiliza enlaces mailbox:/// puede desencadenar descargas automáticas no solicitadas de archivos .pdf al escritorio o directorio personal del usuario sin prev…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2025-5986
|
2026-04-14 00:17 |
2025-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2470
|
7.8 |
HIGH
Local
|
mozilla
|
vpn
|
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root.
*This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerabili…
|
CWE-269
Improper Privilege Management
|
CVE-2025-5687
|
2026-04-14 00:17 |
2025-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|