CVE-2025-1014
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 4, 2025
Updated: Feb 6, 2025
CWE ID 295
Summary
CVE-2025-1014 is a vulnerability affecting Firefox versions prior to 135 and Firefox ESR versions below 128.7, as well as Thunderbird versions below 128.7 and 135. This issue stems from a failure to adequately verify certificate length during the addition process for certificates in a certificate store. Despite its implications, the vulnerability only poses a significant risk when dealing with untrusted data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Mozilla Thunderbird
- Mozilla Firefox
Affected Vendors
- Mozilla