9.8

CVSS3.1

CVE-2025-11708 - Use-after-free in MediaTrackGraphImpl::GetInstance()

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

📅 Published: Oct. 14, 2025, 12:27 p.m. 🔄 Last Modified: April 20, 2026, 7:15 p.m.

8.1

CVSS3.1

CVE-2025-11713 - Potential user-assisted code execution in “Copy as cURL” command

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thund…

📅 Published: Oct. 14, 2025, 12:27 p.m. 🔄 Last Modified: April 20, 2026, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-11710 - Cross-process information leaked due to malicious IPC messages

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

📅 Published: Oct. 14, 2025, 12:27 p.m. 🔄 Last Modified: April 20, 2026, 7:15 p.m.

8.8

CVSS3.1

CVE-2025-11714 - Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 1…

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerabili…

📅 Published: Oct. 14, 2025, 12:27 p.m. 🔄 Last Modified: April 20, 2026, 7:15 p.m.

6.5

CVSS3.1

CVE-2025-11711 - Some non-writable Object properties could be modified

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

📅 Published: Oct. 14, 2025, 12:27 p.m. 🔄 Last Modified: April 20, 2026, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-11709 - Out of bounds read/write in a privileged process triggered by WebGL textures

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

📅 Published: Oct. 14, 2025, 12:27 p.m. 🔄 Last Modified: April 20, 2026, 6 p.m.

8.5

CVSS4.0

CVE-2025-9067 - Rockwell Automation FactoryTalk® Linx Privilege Escalation Vulnerabilities

A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges…

📅 Published: Oct. 14, 2025, 12:24 p.m. 🔄 Last Modified: Oct. 20, 2025, 8:16 p.m.

8.7

CVSS4.0

CVE-2025-9124 - Rockwell Automation Compact GuardLogix® 5370 Denial-Of-Service Vulnerability

A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a crafted CIP unconnected explicit message is sent. This can result in a major non-recoverable fault.

📅 Published: Oct. 14, 2025, 12:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-9068 - Rockwell Automation FactoryTalk® Linx Privilege Escalation Vulnerabilities

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This a…

📅 Published: Oct. 14, 2025, 12:23 p.m. 🔄 Last Modified: Oct. 24, 2025, 5:27 p.m.

8.7

CVSS4.0

CVE-2025-9064 - Rockwell Automation FactoryTalk View Machine Edition Path Traversal

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

📅 Published: Oct. 14, 2025, 12:22 p.m. 🔄 Last Modified: Oct. 28, 2025, 3:20 p.m.
Total resulsts: 349182
Page 3447 of 34,919
« previous page » next page
Filters