Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Mozilla — Vulnerabilities & Security Advisories 1763

Browse all 1763 CVE security advisories affecting Mozilla. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-3029 URL Bar Spoofing via non-BMP Unicode characters — Firefox 4.3 -2025-04-01
CVE-2025-3028 Use-after-free triggered by XSLTProcessor — Firefox 8.8 -2025-04-01
CVE-2025-2857 Incorrect handle could lead to sandbox escapes — Firefox 9.6AICriticalAI2025-03-27
CVE-2025-26696 Crafted email message incorrectly shown as being encrypted — Thunderbird 7.5 -2025-03-10
CVE-2025-26695 Downloading of OpenPGP keys from WKD used incorrect padding — Thunderbird 5.3 -2025-03-10
CVE-2025-27425 QR code user confirmation bypass with invalid protocol — Firefox for iOS 4.3 -2025-03-04
CVE-2025-1943 Memory safety bugs fixed in Firefox 136 and Thunderbird 136 — Firefox 9.8 -2025-03-04
CVE-2025-27424 Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme — Firefox for iOS 4.3 -2025-03-04
CVE-2025-27426 Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error page — Firefox for iOS 4.7 -2025-03-04
CVE-2025-1938 Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8 — Firefox 9.8 -2025-03-04
CVE-2025-1937 Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8 — Firefox 9.8 -2025-03-04
CVE-2025-1936 Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents — Firefox 7.5 -2025-03-04
CVE-2025-1942 Disclosure of uninitialized memory when .toUpperCase() causes string to get longer — Firefox--2025-03-04
CVE-2025-1935 Clickjacking the registerProtocolHandler info-bar — Firefox 7.1 -2025-03-04
CVE-2025-1934 Unexpected GC during RegExp bailout processing — Firefox 6.5 -2025-03-04
CVE-2025-1941 Lock screen setting bypass in Firefox Focus for Android — Firefox 9.8 -2025-03-04
CVE-2025-1933 JIT corruption of WASM i32 return values on 64-bit CPUs — Firefox 8.1 -2025-03-04
CVE-2025-1940 Android Intent confirmation prompt tapjacking using Select options — Firefox 4.3 -2025-03-04
CVE-2025-1932 Inconsistent comparator in XSLT sorting led to out-of-bounds access — Firefox 8.8 -2025-03-04
CVE-2025-1939 Tapjacking in Android Custom Tabs using transition animations — Firefox 6.5 -2025-03-04
CVE-2025-1931 Use-after-free in WebTransportChild — Firefox 9.8 -2025-03-04
CVE-2025-1930 AudioIPC StreamData could trigger a use-after-free in the Browser process — Firefox 10.0 -2025-03-04
CVE-2025-1414 Memory safety bugs fixed in Firefox 135.0.1 — Firefox 9.8 -2025-02-18
CVE-2025-1015 Unsanitized address book fields — Thunderbird 6.1 -2025-02-04
CVE-2025-1020 Memory safety bugs fixed in Firefox 135 and Thunderbird 135 — Firefox 9.8 -2025-02-04
CVE-2025-1016 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7 — Firefox 9.8 -2025-02-04
CVE-2025-1017 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 — Firefox 9.8 -2025-02-04
CVE-2025-0510 Address of e-mail sender can be spoofed by malicious email — Thunderbird 4.3 -2025-02-04
CVE-2025-1014 Certificate length was not properly checked — Firefox 8.1 -2025-02-04
CVE-2025-1013 Potential opening of private browsing tabs in normal browsing windows — Firefox 5.9 -2025-02-04

This page lists every published CVE security advisory associated with Mozilla. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.