Search CVE reports


Toggle filters

341 – 350 of 2385 results


CVE-2025-3028

Medium priority

Some fixes available 1 of 12

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

9 affected packages

mozjs52, mozjs78, firefox, thunderbird, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs78 Not in release Not in release Ignored Not in release
firefox Not affected Not affected Not affected Not in release
thunderbird Not affected Not affected Fixed Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs91 Not in release Not in release Ignored Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
Show all 9 packages Show less packages

CVE-2024-8176

Medium priority

Some fixes available 6 of 82

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to...

23 affected packages

cadaver, apache2, apr-util, cmake, ghostscript...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cadaver Needs evaluation Needs evaluation Needs evaluation Ignored Needs evaluation
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Ignored Needs evaluation
vnc4 Not in release Not in release Not in release Not in release Needs evaluation
wbxml2 Needs evaluation Needs evaluation Needs evaluation Ignored Needs evaluation
swish-e Needs evaluation Needs evaluation Needs evaluation Ignored Needs evaluation
insighttoolkit4 Not in release Not in release Needs evaluation Ignored Needs evaluation
gdcm Not affected Not affected Not affected Not affected Needs evaluation
ayttm Not in release Not in release Not in release Not in release
cableswig Not in release Not in release Not in release Not in release
coin3 Not affected Not affected Not affected Not affected Needs evaluation
matanza Ignored Ignored Ignored Ignored Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Ignored Needs evaluation
vtk Not in release Not in release Not in release Not in release
smart Not in release Not in release Not in release Not in release Needs evaluation
firefox Not affected Not affected Not affected Not in release
thunderbird Not affected Not affected Not affected Not in release
libxmltok Not in release Needs evaluation Needs evaluation Ignored Needs evaluation
expat Fixed Fixed Fixed Ignored Ignored
Show all 23 packages Show less packages

CVE-2025-26696

Medium priority
Fixed

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136...

1 affected package

thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Fixed Not in release
Show less packages

CVE-2025-26695

Medium priority
Fixed

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and...

1 affected package

thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Fixed Not in release
Show less packages

CVE-2025-27426

Medium priority
Not affected

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
Show less packages

CVE-2025-27425

Medium priority
Not affected

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
Show less packages

CVE-2025-27424

Medium priority
Not affected

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
Show less packages

CVE-2025-1943

Medium priority

Some fixes available 2 of 13

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...

9 affected packages

mozjs52, firefox, thunderbird, mozjs38, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Not in release Ignored Ignored
firefox Not affected Not affected Not affected Fixed
thunderbird Not affected Not affected Fixed Not in release
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
Show all 9 packages Show less packages

CVE-2025-1942

Medium priority

Some fixes available 2 of 13

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

9 affected packages

firefox, thunderbird, mozjs52, mozjs38, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed
thunderbird Not affected Not affected Fixed Not in release
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs68 Not in release Not in release Not in release Ignored
mozjs78 Not in release Not in release Ignored Not in release
mozjs91 Not in release Not in release Ignored Not in release
mozjs102 Not in release Ignored Ignored Not in release
mozjs115 Not in release Ignored Not in release Not in release
Show all 9 packages Show less packages

CVE-2025-1941

Medium priority
Not affected

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
Show less packages