CVE-2025-1932

HIGH

Firefox < 136 and Firefox ESR < 128.8 - Out-of-bounds Read in XSLT Node Sorter

Title source: llm
STIX 2.1

Description

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

Scores

CVSS v3 8.1
EPSS 0.0039
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-125
Status published
Products (7)
mozilla/firefox < 128.8.0
mozilla/firefox < 136.0
Mozilla/Firefox 128.8 - 128.*
Mozilla/Firefox 136
Mozilla/Thunderbird 128.8 - 128.*
Mozilla/Thunderbird 136
mozilla/thunderbird ] - 128.8.0
Published Mar 04, 2025
Tracked Since Feb 18, 2026