CVE-2025-3031Medium· 6.5▾ SunlitAn attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
firefox < 137.0thunderbird < 137.0Upgrade past the affected range:
firefox 137.0thunderbird 137.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100766Medium· 4.3Information disclosure in the Networking: JAR component
CVE-2026-92070Medium· 4.3Information disclosure in the Networking component
CVE-2026-8706Medium· 6.5Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies
CVE-2026-8967High· 7.5Information disclosure in the Graphics: WebGPU component
CVE-2026-8966High· 7.5Information disclosure in the IP Protection component