7.1
CVE-2025-1940 - Android Intent confirmation prompt tapjacking using Select options
A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.
6.5
CVE-2025-1934 - Unexpected GC during RegExp bailout processing
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
8.1
CVE-2025-1932 - Inconsistent comparator in XSLT sorting led to out-of-bounds access
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
7.6
CVE-2025-1933 - JIT corruption of WASM i32 return values on 64-bit CPUs
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
7.5
CVE-2025-1931 - Use-after-free in WebTransportChild
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
3.9
CVE-2025-1939 - Tapjacking in Android Custom Tabs using transition animations
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.
8.8
CVE-2025-1930 - AudioIPC StreamData could trigger a use-after-free in the Browser process
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128β¦
6.9
CVE-2025-1925 - Open5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service
A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The attack can be launched reβ¦
7.1
CVE-2025-22226 -
VMware ESXi, Workstation, and Fusion containΒ an information disclosure vulnerability due to an out-of-bounds read in HGFS.Β A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
8.2
CVE-2025-22225 -
VMware ESXi contains an arbitrary writeΒ vulnerability.Β A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.