Mozilla Firefox等都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Firefox ESR是Firefox(Web浏览器)的一个延长支持版本。Mozilla Thunderbird是一套从Mozilla Application Suite独立出来的电子邮件客户端软件。 Mozilla多款产品存在安全漏洞,该漏洞源于自定义协议处理劫持。以下产品及版本受到影响:Firefox 136之前版本、Firefox ESR 128.8之前版本、Th
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mozilla | Firefox | 128.8≤ 128.* |
unaffected |
136≤ * |
unaffected | ||
| Mozilla | Thunderbird | 128.8≤ 128.* |
unaffected |
136≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 128.8 ~ 128.* | - |
|
| Mozilla | Thunderbird | 128.8 ~ 128.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-27425 | QR code user confirmation bypass with invalid protocol | |
| CVE-2025-27426 | Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error pag | |
| CVE-2025-27424 | Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme | |
| CVE-2025-1943 | Memory safety bugs fixed in Firefox 136 and Thunderbird 136 | |
| CVE-2025-1937 | Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR | |
| CVE-2025-1938 | Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbi | |
| CVE-2025-1942 | Disclosure of uninitialized memory when .toUpperCase() causes string to get longer | |
| CVE-2025-1936 | Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents | |
| CVE-2025-1941 | Lock screen setting bypass in Firefox Focus for Android | |
| CVE-2025-1934 | Unexpected GC during RegExp bailout processing | |
| CVE-2025-1932 | Inconsistent comparator in XSLT sorting led to out-of-bounds access | |
| CVE-2025-1940 | Android Intent confirmation prompt tapjacking using Select options | |
| CVE-2025-1933 | JIT corruption of WASM i32 return values on 64-bit CPUs | |
| CVE-2025-1931 | Use-after-free in WebTransportChild | |
| CVE-2025-1939 | Tapjacking in Android Custom Tabs using transition animations | |
| CVE-2025-1930 | AudioIPC StreamData could trigger a use-after-free in the Browser process |
No comments yet