Search CVE reports


Toggle filters

511 – 520 of 2559 results


CVE-2025-3032

Medium priority

Some fixes available 1 of 12

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

9 affected packages

mozjs52, firefox, mozjs102, mozjs115, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Needs evaluation Ignored
firefox Not affected Not affected Not affected Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
thunderbird Not affected Not affected Fixed Not in release
Show all 9 packages Show less packages

CVE-2025-3031

Medium priority

Some fixes available 1 of 12

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

9 affected packages

mozjs52, firefox, mozjs102, mozjs115, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Needs evaluation Ignored
firefox Not affected Not affected Not affected Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
thunderbird Not affected Not affected Fixed Not in release
Show all 9 packages Show less packages

CVE-2025-3030

Medium priority

Some fixes available 1 of 12

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been...

9 affected packages

mozjs52, firefox, mozjs102, mozjs115, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Needs evaluation Ignored
firefox Not affected Not affected Not affected Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
thunderbird Not affected Not affected Fixed Not in release
Show all 9 packages Show less packages

CVE-2025-3029

Medium priority

Some fixes available 1 of 12

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and...

9 affected packages

mozjs52, firefox, mozjs102, mozjs115, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Needs evaluation Ignored
firefox Not affected Not affected Not affected Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
thunderbird Not affected Not affected Fixed Not in release
Show all 9 packages Show less packages

CVE-2025-3028

Medium priority

Some fixes available 1 of 12

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

9 affected packages

mozjs52, firefox, mozjs102, mozjs115, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Needs evaluation Ignored
firefox Not affected Not affected Not affected Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
thunderbird Not affected Not affected Fixed Not in release
Show all 9 packages Show less packages

CVE-2024-8176

Medium priority

Some fixes available 6 of 89

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to...

23 affected packages

xmlrpc-c, wbxml2, swish-e, cadaver, tdom...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
cmake Not affected Not affected Not affected Not affected Not affected
coin3 Not affected Not affected Not affected Not affected Needs evaluation
expat Fixed Fixed Fixed Ignored Ignored
firefox Not affected Not affected Not affected Not in release
gdcm Not affected Not affected Not affected Not affected Needs evaluation
ghostscript Not affected Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
libxmltok Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
matanza Ignored Ignored Ignored Needs evaluation Needs evaluation
smart Not in release Not in release Not in release Not in release Needs evaluation
texlive-bin Not affected Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not affected Not in release
vnc4 Not in release Not in release Not in release Not in release Needs evaluation
vtk Not in release Not in release Not in release Not in release
Show all 23 packages Show less packages

CVE-2025-26696

Medium priority
Fixed

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136...

1 affected package

thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Fixed Not in release
Show less packages

CVE-2025-26695

Medium priority
Fixed

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and...

1 affected package

thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Fixed Not in release
Show less packages

CVE-2025-27426

Medium priority
Not affected

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
Show less packages

CVE-2025-27425

Medium priority
Not affected

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
Show less packages