8.8

CVSS3.1

CVE-2025-6426 - No warning when opening executable terminal files on macOS

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

πŸ“… Published: June 24, 2025, 12:28 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 4:12 p.m.

6.5

CVSS3.1

CVE-2025-6429 - Incorrect parsing of URLs could have allowed embedding of youtube.com

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR…

πŸ“… Published: June 24, 2025, 12:28 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

9.8

CVSS3.1

CVE-2025-6424 - Use-after-free in FontFaceSet

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

πŸ“… Published: June 24, 2025, 12:27 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

4.3

CVSS3.1

CVE-2025-6425 - The WebCompat WebExtension shipped with Firefox exposed a persistent UUID

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128…

πŸ“… Published: June 24, 2025, 12:27 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

7.1

CVSS4.0

CVE-2025-39205 -

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

πŸ“… Published: June 24, 2025, 12:13 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:36 p.m.

8.5

CVSS4.0

CVE-2025-39204 -

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

πŸ“… Published: June 24, 2025, 12:01 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 6:42 p.m.

7.1

CVSS4.0

CVE-2025-39203 -

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop.

πŸ“… Published: June 24, 2025, 11:57 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 6:45 p.m.

8.3

CVSS4.0

CVE-2025-39202 -

A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.

πŸ“… Published: June 24, 2025, 11:51 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 6:52 p.m.

6.9

CVSS4.0

CVE-2025-39201 -

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.

πŸ“… Published: June 24, 2025, 11:46 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 6:56 p.m.

8.7

CVSS4.0

CVE-2025-2403 -

A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could potentially cause critical functions like LDCM (Line Distance Communication Module) to malfunction.

πŸ“… Published: June 24, 2025, 11:33 a.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.
Total resulsts: 343924
Page 4377 of 34,393
Β« previous page Β» next page
Filters