CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0CVE-2025-10532 – Incorrect boundary conditions in the JavaScript: GC component
https://notcve.org/view.php?id=CVE-2025-10532
16 Sep 2025 — This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Incorrect boundary conditions in the JavaScript. • https://bugzilla.mozilla.org/show_bug.cgi?id=1979502 • CWE-125: Out-of-bounds Read CWE-754: Improper Check for Unusual or Exceptional Conditions •
CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0CVE-2025-10529 – Same-origin policy bypass in the Layout component
https://notcve.org/view.php?id=CVE-2025-10529
16 Sep 2025 — This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. • https://bugzilla.mozilla.org/show_bug.cgi?id=1970490 • CWE-942: Permissive Cross-domain Policy with Untrusted Domains •
CVSS: 7.6EPSS: 0%CPEs: 4EXPL: 0CVE-2025-10528 – Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component
https://notcve.org/view.php?id=CVE-2025-10528
16 Sep 2025 — This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Sandbox escape due to undefined behavior, invalid pointer in the Graphics. • https://bugzilla.mozilla.org/show_bug.cgi?id=1986185 • CWE-693: Protection Mechanism Failure CWE-824: Access of Uninitialized Pointer •
CVSS: 7.6EPSS: 0%CPEs: 4EXPL: 0CVE-2025-10527 – Sandbox escape due to use-after-free in the Graphics: Canvas2D component
https://notcve.org/view.php?id=CVE-2025-10527
16 Sep 2025 — This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Sandbox escape due to use-after-free in the Graphics. • https://bugzilla.mozilla.org/show_bug.cgi?id=1984825 • CWE-416: Use After Free •
CVSS: 9.0EPSS: 0%CPEs: 5EXPL: 0CVE-2025-10533 – Integer overflow in the SVG component
https://notcve.org/view.php?id=CVE-2025-10533
16 Sep 2025 — This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Integer overflow in the SVG component. • https://bugzilla.mozilla.org/show_bug.cgi?id=1980788 • CWE-190: Integer Overflow or Wraparound •
CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0CVE-2025-55029 – Malicious scripts could spam popups for denial of service attacks
https://notcve.org/view.php?id=CVE-2025-55029
19 Aug 2025 — Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks This vulnerability affects Firefox for iOS < 142. Los scripts maliciosos podrían eludir el bloqueador de ventanas emergentes para enviar spam a nuevas pestañas, lo que podría provocar ataques de denegación de servicio. Esta vulnerabilidad afecta a Firefox para iOS < 142. • https://bugzilla.mozilla.org/show_bug.cgi?id=1973577 • CWE-400: Uncontrolled Resource Consumption •
CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0CVE-2025-55031 – Passkey phishing within Bluetooth range
https://notcve.org/view.php?id=CVE-2025-55031
19 Aug 2025 — Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142. Las páginas maliciosas podrían usar Firefox para iOS para transferir enlaces FIDO al sistema operativo y activar el transporte de claves de acceso híbridas. Un atacante ... • https://bugzilla.mozilla.org/show_bug.cgi?id=1979499 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0CVE-2025-55028 – JavaScript alerts could impede UI interaction or allow denial of service attacks
https://notcve.org/view.php?id=CVE-2025-55028
19 Aug 2025 — Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142. Los scripts maliciosos que utilizan alertas JavaScript repetitivas podrían impedir la interacción del usuario del cliente en algunos escenarios y permitir ataques de denegación de servicio. Esta vulnerabilidad afecta a Firefox para iOS < 142. • https://bugzilla.mozilla.org/show_bug.cgi?id=1850240 • CWE-400: Uncontrolled Resource Consumption •
CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0CVE-2025-55030 – Content-Disposition headers incorrectly ignored for some MIME types
https://notcve.org/view.php?id=CVE-2025-55030
19 Aug 2025 — Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks This vulnerability affects Firefox for iOS < 142. Firefox para iOS no respetaría un encabezado Content-Disposition de tipo Attachment y mostraría incorrectamente el contenido en línea en lugar de descargarlo, lo que potencialmente permitiría ataques XSS. Esta vulnerabilidad afecta a Firefox para iOS < 142. • https://bugzilla.mozilla.org/show_bug.cgi?id=1976304 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVSS: 9.4EPSS: 0%CPEs: 1EXPL: 0CVE-2025-54145
https://notcve.org/view.php?id=CVE-2025-54145
19 Aug 2025 — The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141. El escáner QR podría permitir que se abran sitios web arbitrarios si un usuario fuera engañado para escanear un enlace malicioso que aprovechara el esquema de URL de texto abierto de Firefox. Esta vulnerabilidad afecta a Firefox para iOS < 141. • https://bugzilla.mozilla.org/show_bug.cgi?id=1946122 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
