|
2421
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Al configurar una cookie sin nombre con un signo igual en su valor, se eclipsaban otras cookies. Incluso si la cookie sin nombre se configuraba mediante HTTP y la cookie eclipsada incluía el atributo…
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2025-8037
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2422
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird …
|
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action
|
CVE-2025-8036
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2423
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Thunderbird almacenó en caché las respuestas de preflight de CORS tras los cambios de dirección IP. Esto permitió eludir CORS mediante revinculación de DNS. Esta vulnerabilidad afecta a Firefox < …
|
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action
|
CVE-2025-8036
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2424
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corru…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8035
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2425
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 y Thunderbird 140. Algunos de estos errores mostraron ev…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8035
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2426
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evid…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8034
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2427
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Errores de seguridad de memoria presentes en Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 y Thunderbird 140. Algunos de estos …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-8034
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2428
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-8033
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2429
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
El motor de JavaScript no gestionaba correctamente los generadores cerrados y era posible resumirlos, lo que provocaba una desreferencia nullptr. Esta vulnerabilidad afecta a Firefox < 141, Firefo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-8033
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2430
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thun…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-8032
|
2026-04-14 00:17 |
2025-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|