Vulnerabilities
Vulnerable Software
Mozilla:  >> Firefox  >> 140.3  Security Vulnerabilities
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVSS Score
8.1
EPSS Score
0.003
Published
2025-09-16
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.
CVSS Score
7.5
EPSS Score
0.003
Published
2025-09-16
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
CVSS Score
6.2
EPSS Score
0.002
Published
2025-09-16
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-09-16
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-09-16
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVSS Score
5.4
EPSS Score
0.003
Published
2025-09-16
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
CVSS Score
7.3
EPSS Score
0.003
Published
2025-09-16
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-09-16
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
CVSS Score
7.1
EPSS Score
0.003
Published
2025-09-16
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
CVSS Score
5.3
EPSS Score
0.14
Published
2016-09-06


Contact Us

Shodan ® - All rights reserved