Mozilla Firefox和Mozilla Firefox ESR都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Firefox ESR是Firefox(Web浏览器)的一个延长支持版本。 Mozilla Firefox 145之前版本和Mozilla Firefox ESR 140.5之前版本存在安全漏洞,该漏洞源于WebRTC Audio/Video组件存在释放后重用问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 140.5 ~ 140.* | - |
|
| Mozilla | Thunderbird | 140.5 ~ 140.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-13027 | Memory safety bugs fixed in Firefox 145 and Thunderbird 145 | |
| CVE-2025-13019 | Same-origin policy bypass in the DOM: Workers component | |
| CVE-2025-13017 | Same-origin policy bypass in the DOM: Notifications component | |
| CVE-2025-13018 | Mitigation bypass in the DOM: Security component | |
| CVE-2025-13026 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component | |
| CVE-2025-13024 | JIT miscompilation in the JavaScript Engine: JIT component | |
| CVE-2025-13025 | Incorrect boundary conditions in the Graphics: WebGPU component | |
| CVE-2025-13023 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component | |
| CVE-2025-13016 | Incorrect boundary conditions in the JavaScript: WebAssembly component | |
| CVE-2025-13022 | Incorrect boundary conditions in the Graphics: WebGPU component | |
| CVE-2025-13015 | Spoofing issue in Firefox | |
| CVE-2025-13021 | Incorrect boundary conditions in the Graphics: WebGPU component | |
| CVE-2025-13014 | Use-after-free in the Audio/Video component | |
| CVE-2025-13013 | Mitigation bypass in the DOM: Core & HTML component | |
| CVE-2025-13012 | Race condition in the Graphics component |
No comments yet