Vulnerabilities
Tracked app vulnerabilities
773 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-12084
MEDIUM 5.3
Network 1 apps
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail… |
|
CVE-2025-13836
MEDIUM 7.5
Network 1 apps
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server… |
|
CVE-2025-52331
MEDIUM 6.1
Network 1 apps
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the … |
|
CVE-2025-6075
MEDIUM 5.5
Local 1 apps
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables. |
|
CVE-2025-11716
MEDIUM 6.5
Network 1 apps
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu… |
|
CVE-2025-11712
MEDIUM 6.1
Network 1 apps
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a… |
|
CVE-2025-11711
MEDIUM 6.5
Network 1 apps
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo… |
|
CVE-2025-59502
MEDIUM 7.5
Remote Procedure Call Denial of Service Vulnerability |
|
CVE-2025-10536
MEDIUM 6.2
Local 1 apps
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10532
MEDIUM 6.5
Network 1 apps
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird… |
|
CVE-2025-10531
MEDIUM 5.4
Network 1 apps
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10529
MEDIUM 6.5
Network 1 apps
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3. |
|
CVE-2025-9181
MEDIUM 6.5
Network 1 apps
Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, T… |
|
CVE-2025-53779
MEDIUM 7.2
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2025-8033
MEDIUM 6.5
Network 1 apps
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in… |
|
CVE-2025-8027
MEDIUM 6.5
Network 1 apps
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner… |
|
CVE-2025-49464
MEDIUM 6.5
Network 1 apps
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access. |
|
CVE-2025-46789
MEDIUM 6.5
Network 1 apps
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access. |
|
CVE-2025-49760
MEDIUM 3.5
Windows Storage Spoofing Vulnerability |
|
CVE-2025-5986
MEDIUM 6.5
Network 1 apps
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti… |
|
CVE-2025-2884
MEDIUM 6.6
Local
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with… |
|
CVE-2025-3932
MEDIUM 6.5
Network 1 apps
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse… |
|
CVE-2025-4092
MEDIUM 6.5
Network 1 apps
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-4089
MEDIUM 5.1
Local 1 apps
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t… |
|
CVE-2025-4088
MEDIUM 6.5
Network 1 apps
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo… |
|
CVE-2025-4087
MEDIUM 4.8
Network 1 apps
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou… |
|
CVE-2025-4084
MEDIUM 5.7
Network 1 apps
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi… |
|
CVE-2025-4082
MEDIUM 5.9
Network 1 apps
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate… |
|
CVE-2025-3523
MEDIUM 6.4
Network 1 apps
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove… |
|
CVE-2025-3522
MEDIUM 6.3
Network 1 apps
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a… |
|
CVE-2025-2830
MEDIUM 6.3
Network 1 apps
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t… |
|
CVE-2025-31334
MEDIUM 6.8
Network 1 apps
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR v… |
|
CVE-2025-3031
MEDIUM 6.5
Network 1 apps
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137. |
|
CVE-2025-3028
MEDIUM 6.5
Network 1 apps
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firef… |
|
CVE-2025-26695
MEDIUM 5.3
Local 1 apps
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai… |
|
CVE-2025-1938
MEDIUM 6.5
Network 1 apps
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-1935
MEDIUM 4.3
Network 1 apps
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR… |
|
CVE-2025-1934
MEDIUM 6.5
Network 1 apps
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no… |
|
CVE-2025-1019
MEDIUM 4.3
Network 1 apps
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. … |
|
CVE-2025-1018
MEDIUM 5.3
Network 1 apps
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential sp… |
|
CVE-2025-1015
MEDIUM 5.4
Network 1 apps
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malici… |
|
CVE-2025-1013
MEDIUM 6.5
Network 1 apps
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vu… |
|
CVE-2025-0510
MEDIUM 6.5
Network 1 apps
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vu… |
|
CVE-2025-0243
MEDIUM 5.1
Local 1 apps
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-0242
MEDIUM 6.5
Network 1 apps
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bug… |
|
CVE-2025-0240
MEDIUM 4.0
Local 1 apps
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability w… |
|
CVE-2025-0239
MEDIUM 4.0
Local 1 apps
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Fi… |
|
CVE-2025-0238
MEDIUM 5.3
Network 1 apps
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability … |
|
CVE-2025-0237
MEDIUM 5.4
Network 1 apps
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal bein… |
|
CVE-2024-11708
MEDIUM 6.5
Network 1 apps
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 an… |