ZeroHour

CVE-2025-8033

CVSS 3.1
6.5 medium
EPSS
<1%p30
Published
()
Modified
Description

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.