NVD · CISA KEV · CERT-In
CVE Tracker
Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.
10.0CVE-2025-2857Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a…Firefox9.8CVE-2025-9187Memory safety bugs present in Firefox 141 and Thunderbird 141.Firefox9.8CVE-2025-9179An attacker was able to perform memory corruption in the GMP process which processes encrypted media.Firefox9.8CVE-2025-8042Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads.Firefox9.8CVE-2025-55031Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey…Firefox9.8CVE-2025-54143Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected…Firefox9.8CVE-2025-8044Memory safety bugs present in Firefox 140 and Thunderbird 140.Firefox9.8CVE-2025-8043Focus incorrectly truncated URLs towards the beginning instead of around the origin.Firefox9.8CVE-2025-8038Thunderbird ignored paths when checking the validity of navigations in a frame.Firefox9.8CVE-2025-8031The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP…Firefox9.8CVE-2025-8028On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from…Firefox9.8CVE-2025-6433If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was…Firefox9.8CVE-2025-6424A use-after-free in FontFaceSet resulted in a potentially exploitable crash.Firefox9.8CVE-2025-49710An integer overflow was present in `OrderedHashTable` used by the JavaScript engine.Firefox9.8CVE-2025-49709Certain canvas operations could have lead to memory corruption.Firefox9.8CVE-2025-4918An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object.Firefox9.8CVE-2025-1942When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be…Firefox9.8CVE-2025-1020Memory safety bugs present in Firefox 134 and Thunderbird 134.Firefox9.8CVE-2025-1017Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6.Firefox9.8CVE-2025-1016Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6,…Firefox9.8CVE-2025-1009An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable…Firefox9.8CVE-2025-0247Memory safety bugs present in Firefox 133 and Thunderbird 133.Firefox9.1CVE-2025-54145The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious…Firefox9.1CVE-2025-8037Setting a nameless cookie with an equals sign in the value shadowed other cookies.Firefox9.1CVE-2025-6427An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating…Firefox9.1CVE-2025-4083A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which…Firefox9.1CVE-2025-1941Under certain circumstances, a user opt-in setting that Focus should require authentication before use…Firefox