ZeroHour

CVE-2025-1942

CVSS 3.1
9.8 critical
EPSS
<1%p39
Published
()
Modified
Description

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.