|
1561
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulne…
Update
|
CWE-1332
Improper Handling of Faults that Lead to Instruction Skips
|
CVE-2025-8028
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1562
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
En arm64, una instrucción WASM `br_table` con muchas entradas podría provocar que la etiqueta se alejara demasiado de la instrucción, lo que causaría truncamiento y un cálculo incorrecto de la direcc…
Update
|
CWE-1332
Improper Handling of Faults that Lead to Instruction Skips
|
CVE-2025-8028
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1563
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefo…
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2025-8027
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1564
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
En plataformas de 64 bits, IonMonkey-JIT solo escribía 32 bits del espacio de valor de retorno de 64 bits en la pila. Sin embargo, Baseline-JIT leía los 64 bits completos. Esta vulnerabilidad afecta …
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2025-8027
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1565
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-6436
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1566
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox 139 y Thunderbird 139. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, algunos de…
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-6436
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1567
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the us…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-6435
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1568
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Si un usuario guardó una respuesta desde la pestaña Red en DevTools mediante la opción Guardar como del menú contextual, es posible que el archivo no se haya guardado con la extensión `.download`. Es…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-6435
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1569
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an except…
Update
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-6434
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1570
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
La página de excepción de la función Solo HTTPS, que se mostraba al abrir un sitio web mediante HTTP, carecía de un retardo anti-clickjacking, lo que potencialmente permitía a un atacante engañar al …
Update
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-6434
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|