CVE-2025-1942
🟠 Łataj w tym tygodniu
Wykorzystanie nieinicjalizowanej pamięci w Firefoxie i Thunderbirdzie pozwalało na ujawnienie danych.
CVSS
9.8
EPSS
0.5%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-03-04 14:15:39 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 19:10:01 UTC |
Referencje
- https://bugzilla.mozilla.org/show_bug.cgi?id=1947139 ([email protected]) [Issue Tracking]
- https://www.mozilla.org/security/advisories/mfsa2025-14/ ([email protected]) [Vendor Advisory]
- https://www.mozilla.org/security/advisories/mfsa2025-17/ ([email protected]) [Vendor Advisory]