CVE-2025-1932

HIGH

Mozilla - Out-of-Bounds Access

Title source: llm
STIX 2.1

Description

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

Scores

CVSS v3 8.1
EPSS 0.0018
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-125
Status published
Products (7)
mozilla/firefox < 128.8.0
mozilla/firefox < 136.0
Mozilla/Firefox 128.8 - 128.*
Mozilla/Firefox 136
Mozilla/Thunderbird 128.8 - 128.*
Mozilla/Thunderbird 136
mozilla/thunderbird ] - 128.8.0
Published Mar 04, 2025
Tracked Since Feb 18, 2026