
CVE-2025-8364
https://notcve.org/view.php?id=CVE-2025-8364
19 Aug 2025 — A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141. A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects F... • https://bugzilla.mozilla.org/show_bug.cgi?id=1909609 • CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVE-2025-9184
https://notcve.org/view.php?id=CVE-2025-9184
19 Aug 2025 — Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2. • https://bugzilla.mozilla.org/buglist.cgi?bug_id=1929482%2C1976376%2C1979163%2C1979955 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2025-9187
https://notcve.org/view.php?id=CVE-2025-9187
19 Aug 2025 — Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142 and Thunderbird < 142. • https://bugzilla.mozilla.org/buglist.cgi?bug_id=1825621%2C1970079%2C1976736%2C1979072 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2025-9183
https://notcve.org/view.php?id=CVE-2025-9183
19 Aug 2025 — Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2. • https://bugzilla.mozilla.org/show_bug.cgi?id=1976102 • CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVE-2025-9182
https://notcve.org/view.php?id=CVE-2025-9182
19 Aug 2025 — 'Denial-of-service due to out-of-memory in the Graphics: WebRender component.' This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2. • https://bugzilla.mozilla.org/show_bug.cgi?id=1975837 • CWE-400: Uncontrolled Resource Consumption •

CVE-2025-9186
https://notcve.org/view.php?id=CVE-2025-9186
19 Aug 2025 — Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142. • https://bugzilla.mozilla.org/show_bug.cgi?id=1445758 • CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVE-2025-9185 – Debian Security Advisory 5980-1
https://notcve.org/view.php?id=CVE-2025-9185
19 Aug 2025 — Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. Multiple sec... • https://bugzilla.mozilla.org/buglist.cgi?bug_id=1970154%2C1976782%2C1977166 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2025-9181 – Debian Security Advisory 5980-1
https://notcve.org/view.php?id=CVE-2025-9181
19 Aug 2025 — Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy. For the oldstable distribution (bookworm), these problems have been fixed in version 128.14.0esr-1~deb12u1. ... • https://bugzilla.mozilla.org/show_bug.cgi?id=1977130 • CWE-457: Use of Uninitialized Variable •

CVE-2025-9180 – Debian Security Advisory 5980-1
https://notcve.org/view.php?id=CVE-2025-9180
19 Aug 2025 — 'Same-origin policy bypass in the Graphics: Canvas2D component.' This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy. For the oldstable distribution (bookworm), these problems have been fixed in v... • https://bugzilla.mozilla.org/show_bug.cgi?id=1979782 • CWE-346: Origin Validation Error •

CVE-2025-9179 – Debian Security Advisory 5980-1
https://notcve.org/view.php?id=CVE-2025-9179
19 Aug 2025 — An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution o... • https://bugzilla.mozilla.org/show_bug.cgi?id=1979527 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •