|
2481
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox 138, Thunderbird 138, Firefox ESR 128.10 y Thunderbird 128.10. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-5268
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2482
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox
|
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunder…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-5267
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2483
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox
|
Una vulnerabilidad de clickjacking podría haberse utilizado para engañar a un usuario y que filtrara los datos de su tarjeta de pago a una página maliciosa. Esta vulnerabilidad afecta a Firefox < …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-5267
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2484
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thu…
|
CWE-200
Information Exposure
|
CVE-2025-5266
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2485
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Los elementos de script que cargaban recursos de origen cruzado generaban eventos de carga y error que filtraban información, lo que facilitaba los ataques XS-Leaks. Esta vulnerabilidad afecta a Fire…
|
CWE-200
Information Exposure
|
CVE-2025-5266
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2486
|
4.8 |
MEDIUM
Local
|
mozilla
|
firefox
|
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user'…
|
CWE-77
Command Injection
|
CVE-2025-5265
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2487
|
4.8 |
MEDIUM
Local
|
mozilla
|
firefox
|
Debido a la insuficiente capacidad de escape del carácter "&" en la función "Copiar como cURL", un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la ejecuc…
|
CWE-77
Command Injection
|
CVE-2025-5265
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2488
|
4.8 |
MEDIUM
Local
|
mozilla
|
firefox
|
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's …
|
CWE-77
Command Injection
|
CVE-2025-5264
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2489
|
4.8 |
MEDIUM
Local
|
mozilla
|
firefox
|
Debido a la insuficiente capacidad de escape del carácter de nueva línea en la función "Copiar como cURL", un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la…
|
CWE-77
Command Injection
|
CVE-2025-5264
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2490
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Fir…
|
CWE-346
Origin Validation Error
|
CVE-2025-5263
|
2026-04-14 00:17 |
2025-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|