Where
AND
-Infinity
0
Severity
5.4
EPSS
0.08%
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.

1 / 5
Source: Red Hat
First published (updated )
Severity
6.1
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C

Microsoft Edge (Chromium-based) Spoofing Vulnerability

First published (updated )
Severity
6.6
Code Injection
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L/E:U/RL:O/RC:C

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:T/RC:C

Microsoft Edge (Chromium-based) Spoofing Vulnerability

1 / 3
Source: Microsoft
First published (updated )
Severity
6.6
Use After Free
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L/E:U/RL:O/RC:C

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

Microsoft Edge (Chromium-based) Spoofing Vulnerability

1 / 3
Source: Microsoft
First published (updated )
Severity
6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability.

1 / 2
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Microsoft Edge (Chromium-based) Spoofing Vulnerability

First published (updated )
Severity
6.1
EPSS
0.05%
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Chromium: CVE-2024-8907 Insufficient data validation in Omnibox

1 / 3
Source: Microsoft
First published (updated )
Severity
4.7
AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

First published (updated )
Severity
6.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C

Microsoft Edge for Android Spoofing Vulnerability

First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-3735 Inappropriate implementation in Web API Permission Prompts

1 / 3
First published (updated )
Severity
4.3
EPSS
0.19%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

Microsoft Edge (Chromium-based) Spoofing Vulnerability

First published (updated )
Severity
5.4
EPSS
0.12%
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

First published (updated )
Severity
4.3
EPSS
0.08%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2024-0805 Inappropriate implementation in Downloads

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.05%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2024-0811 Inappropriate implementation in Extensions API

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.05%
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-5485 Inappropriate implementation in Autofill

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.16%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-5858 Inappropriate implementation in WebApp Provider

1 / 3
Source: Microsoft
First published (updated )
Severity
5.3
EPSS
0.05%
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Chromium: CVE-2024-0333 Insufficient data validation in Extensions

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
EPSS
0.08%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Chromium: CVE-2024-0814 Incorrect security UI in Payments

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
EPSS
0.06%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2025-5066 Inappropriate implementation in Messages

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
EPSS
0.06%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-5067 Inappropriate implementation in Tab Strip

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
EPSS
0.06%
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-5281 Inappropriate implementation in BFCache

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
EPSS
0.06%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2025-5065 Inappropriate implementation in FileSystemAccess API

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
EPSS
0.06%
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-5064 Inappropriate implementation in Background Fetch API

1 / 3
Source: Microsoft
First published (updated )
Severity
6.3
EPSS
0.03%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Chromium: CVE-2025-4051 Insufficient data validation in DevTools

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
EPSS
0.10%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Chromium: CVE-2023-6512 Inappropriate implementation in Web Browser UI

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.05%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2024-0810 Insufficient policy enforcement in DevTools

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
Infoleak
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka 'Microsoft Browser Information Disclosure Vulnerability'.

1 / 3
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203