|
2371
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Un atacante logró realizar una lectura o escritura fuera de los límites en un objeto JavaScript al confundir el tamaño del índice de la matriz. Esta vulnerabilidad afecta a Firefox (versión anterior …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2025-4919
|
2026-04-14 00:17 |
2025-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2372
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbi…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2025-4918
|
2026-04-14 00:17 |
2025-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2373
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Un atacante logró realizar una lectura o escritura fuera de los límites en un objeto "Promise" de JavaScript. Esta vulnerabilidad afecta a Firefox (versión anterior a 138.0.4), Firefox ESR (versión a…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2025-4918
|
2026-04-14 00:17 |
2025-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2374
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-4093
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2375
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Error de seguridad de memoria presente en Firefox ESR 128.9 y Thunderbird 128.9. Este error mostró evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, podría haberse explota…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-4093
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2376
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-4092
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2377
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox 137 y Thunderbird 137. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con el esfuerzo suficiente, algunos…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-4092
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2378
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-4091
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2379
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox 137, Thunderbird 137, Firefox ESR 128.9 y Thunderbird 128.9. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos qu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-4091
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2380
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-4090
|
2026-04-14 00:17 |
2025-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|