|
1541
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-8038
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1542
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird ignoraba las rutas al comprobar la validez de las navegaciones en un frame. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141 y Thunderbird < …
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-8038
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1543
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerab…
Update
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2025-8037
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1544
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Al configurar una cookie sin nombre con un signo igual en su valor, se eclipsaban otras cookies. Incluso si la cookie sin nombre se configuraba mediante HTTP y la cookie eclipsada incluía el atributo…
Update
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2025-8037
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1545
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird …
Update
|
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action
|
CVE-2025-8036
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1546
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird almacenó en caché las respuestas de preflight de CORS tras los cambios de dirección IP. Esto permitió eludir CORS mediante revinculación de DNS. Esta vulnerabilidad afecta a Firefox < …
Update
|
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action
|
CVE-2025-8036
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1547
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corru…
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8035
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1548
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 y Thunderbird 140. Algunos de estos errores mostraron ev…
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8035
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1549
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evid…
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8034
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1550
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 y Thunderbird 140. Algunos de estos …
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8034
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|