CVE-2025-3608

MEDIUM

Firefox < 137.0.2 - Memory Corruption via Race Condition in nsHttpTransaction

Title source: llm
STIX 2.1

Description

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability was fixed in Firefox 137.0.2.

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362
Status published
Products (2)
mozilla/firefox < 137.0.2
Mozilla/Firefox 137.0.2
Published Apr 15, 2025
Tracked Since Feb 18, 2026