8.1 CVE-2025-9180

 

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
https://nvd.nist.gov/vuln/detail/CVE-2025-9180

Categories

CWE-346

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* < 115.27.0
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* < 142.0
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* >= 128.0 < 128.14.0
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* >= 140.0 < 140.2.0
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* < 128.14.0
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* < 142.0
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* >= 140.0 < 140.2.0


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry