CVE-2025-3028

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 7, 2025
CWE ID 416

Summary

CVE-2025-3028 is a use-after-free vulnerability that can be exploited when JavaScript code runs during the XSLTProcessor document transformation in Firefox versions prior to 137, Firefox ESR versions prior to 115.22 and 128.9, Thunderbird versions prior to 137, and Thunderbird versions prior to 128.9. The issue arises when memory is not properly managed following the execution of JavaScript code, leaving it susceptible to manipulation and potential crashes or arbitrary code execution. This weakness in the browsers and email client could potentially allow an attacker to execute malicious code or gain elevated privileges within affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share