Mozilla Firefox和Mozilla Thunderbird都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Thunderbird是一套从Mozilla Application Suite独立出来的电子邮件客户端软件。该软件支持IMAP、POP邮件协议以及HTML邮件格式。 Mozilla Firefox 136之前版本和Mozilla Thunderbird 136之前版本存在安全漏洞,该漏洞源于未初始化内存使用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mozilla | Firefox | 136≤ * |
unaffected |
| Mozilla | Thunderbird | 136≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 136 ~ * | - |
|
| Mozilla | Thunderbird | 136 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-27425 | QR code user confirmation bypass with invalid protocol | |
| CVE-2025-27426 | Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error pag | |
| CVE-2025-27424 | Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme | |
| CVE-2025-1943 | Memory safety bugs fixed in Firefox 136 and Thunderbird 136 | |
| CVE-2025-1937 | Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR | |
| CVE-2025-1938 | Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbi | |
| CVE-2025-1935 | Clickjacking the registerProtocolHandler info-bar | |
| CVE-2025-1936 | Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents | |
| CVE-2025-1941 | Lock screen setting bypass in Firefox Focus for Android | |
| CVE-2025-1934 | Unexpected GC during RegExp bailout processing | |
| CVE-2025-1932 | Inconsistent comparator in XSLT sorting led to out-of-bounds access | |
| CVE-2025-1940 | Android Intent confirmation prompt tapjacking using Select options | |
| CVE-2025-1933 | JIT corruption of WASM i32 return values on 64-bit CPUs | |
| CVE-2025-1931 | Use-after-free in WebTransportChild | |
| CVE-2025-1939 | Tapjacking in Android Custom Tabs using transition animations | |
| CVE-2025-1930 | AudioIPC StreamData could trigger a use-after-free in the Browser process |
No comments yet