|
1851
|
7.7 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Al segmentar texto especialmente manipulado, la segmentación corrompía la memoria y provocaba un bloqueo que podía explotarse. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128.6.
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2025-0241
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1852
|
4.0 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128…
Update
|
CWE-416
Use After Free
|
CVE-2025-0240
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1853
|
4.0 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
Analizar un módulo de JavaScript como JSON podría, en algunas circunstancias, provocar un acceso entre compartimentos, lo que puede dar lugar a use-after-free. Esta vulnerabilidad afecta a Firefox &l…
Update
|
CWE-416
Use After Free
|
CVE-2025-0240
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1854
|
4.0 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbir…
Update
|
CWE-295
Improper Certificate Validation
|
CVE-2025-0239
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1855
|
4.0 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
Al utilizar Alt-Svc, ALPN no validó correctamente los certificados cuando el servidor original redireccionaba a un sitio inseguro. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128…
Update
|
CWE-295
Improper Certificate Validation
|
CVE-2025-0239
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1856
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 12…
Update
|
CWE-416
Use After Free
|
CVE-2025-0238
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1857
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Suponiendo que se haya producido una asignación de memoria fallida y controlada, un atacante podría haber provocado un error de use-after-free, lo que habría provocado un bloqueo potencialmente explo…
Update
|
CWE-416
Use After Free
|
CVE-2025-0238
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1858
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2025-0237
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1859
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
La WebChannel API, que se utiliza para transportar información diversa entre procesos, no comprobó el principal de envío, sino que aceptó el principal enviado. Esto podría haber provocado ataques de …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2025-0237
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1860
|
6.1 |
MEDIUM
Network
|
jquery drupal debian fedoraproject oracle netapp opensuse tenable
|
jquery drupal debian_linux fedora agile_product_lifecycle_management_for_process application_testing_suite banking_digital_experience blockchain_platform communications_applic…
|
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2020-11022
|
2026-04-14 00:16 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|