Multiple IBM SmartCloud Analytics Vulnerabilities
July 28, 2025Multiple D-Link DIR-513 Vulnerabilities
July 28, 2025Multiple IBM SmartCloud Analytics Vulnerabilities
July 28, 2025Multiple D-Link DIR-513 Vulnerabilities
July 28, 2025Severity
High
Analysis Summary
CVE-2025-8044 CVSS:8.8
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVE-2025-8043 CVSS:6.5
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by incorrectly truncated URLs towards the beginning instead of around the origin. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to bypass security restrictions.
CVE-2025-8035 CVSS:8.8
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVE-2025-8040 CVSS:8.8
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVE-2025-8034 CVSS:8.8
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVE-2025-8039 CVSS:6.5
Mozilla Firefox could allow a remote attacker to obtain sensitive information, caused by search terms persisting in the URL bar even after navigating away from the search page. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2025-8038 CVSS:6.5
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by the failure to correctly enforce CSP frame-src for paths. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to bypass security restrictions.
CVE-2025-8033 CVSS:6.5
Mozilla Firefox is vulnerable to a denial of service, caused by the incorrect JavaScript state machine for generators. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to trigger a NULL pointer dereference error.
Impact
- Code Execution
- Security Bypass
- Information Disclosure
- Denial of Service
Indicators of Compromise
CVE
CVE-2025-8044
CVE-2025-8043
CVE-2025-8035
CVE-2025-8040
CVE-2025-8034
CVE-2025-8039
CVE-2025-8038
CVE-2025-8033
Affected Vendors
Affected Products
- Mozilla Thunderbird 128.12
- Mozilla Firefox ESR 115.25
- Mozilla Thunderbird 140.0
- Mozilla Firefox ESR 140.0
- Mozilla Firefox ESR 128.12
- Mozilla Firefox 140.0
Remediation
Refer to Mozilla Firefox Website for patch, upgrade, or suggested workaround information.