FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- clickjacking vulnerability

Affected packages
firefox-esr < 128.11.0
firefox < 139.0,2

Details

VuXML ID 63268efe-4222-11f0-976e-b42e991fc52e
Discovery 2025-05-27
Entry 2025-06-05

security@mozilla.org reports:

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page.

References

CVE Name CVE-2025-5267
URL https://nvd.nist.gov/vuln/detail/CVE-2025-5267