CVE-2025-1014

HIGH

Firefox <135 - Info Disclosure

Title source: llm
STIX 2.1

Description

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

Scores

CVSS v3 8.8
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (8)
mozilla/firefox < 128.7.0
mozilla/firefox < 135.0
Mozilla/Firefox 128.7 - 128.*
Mozilla/Firefox 135
mozilla/thunderbird 128.0.1 - 128.7.0
Mozilla/Thunderbird 128.7 - 128.*
mozilla/thunderbird 131.0 - 135.0
Mozilla/Thunderbird 135
Published Feb 04, 2025
Tracked Since Feb 18, 2026