CVE-2025-4086 – Mozilla Firefox and Thunderbird File Extension Disclosure Vulnerability
The following table lists the changes that have been made to the CVE-2025-4086 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-4083 – Firefox JavaScript URI Isolation Bypass
A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document’s process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < […]
CVE-2025-4092 – Firefox Memory Corruption Arbitrary Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-4092 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-4084 – “Firefox/Thunderbird Escaping Vulnerability (Local Code Execution)”
The following table lists the changes that have been made to the CVE-2025-4084 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-4064 – ScriptAndTools Online-Travling-System Remote File Inclusion Vulnerability
The following table lists the changes that have been made to the CVE-2025-4064 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-4062 – Apache Code-Projects Theater Seat Booking System Stack-Based Buffer Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-4062 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-4082 – Mozilla Firefox WebGL Out-of-Bounds Read RCE
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird […]
CVE-2025-4063 – Code-projects Student Information Management System Buffer Overflow
The following table lists the changes that have been made to the CVE-2025-4063 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-3301 – Marvell Series 2 DPA Vulnerability: ECDH and EdDSA Countermeasures Missing
The following table lists the changes that have been made to the CVE-2025-3301 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 29, 2025 Action […]
CVE-2025-2817 – Mozilla Firefox System File Privilege Escalation
Mozilla Firefox’s update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, […]