CVE-2025-1014

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 4, 2025
Updated: Feb 6, 2025
CWE ID 295

Summary

CVE-2025-1014 is a vulnerability affecting Firefox versions prior to 135 and Firefox ESR versions below 128.7, as well as Thunderbird versions below 128.7 and 135. This issue stems from a failure to adequately verify certificate length during the addition process for certificates in a certificate store. Despite its implications, the vulnerability only poses a significant risk when dealing with untrusted data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird
  • Mozilla Firefox

Affected Vendors

  • Mozilla