Severity
8.8HIGHNVD
OSV9.8
EPSS
0.2%
top 56.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateJul 22

Description

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDmozilla/firefox< 128.7.0+1
NVDmozilla/thunderbird128.0.1128.7.0+1
Ubuntumozilla/firefox< 135.0+build2-0ubuntu0.20.04.1
Debianmozilla/thunderbird< 1:128.7.0esr-1~deb11u1+3

🔴Vulnerability Details

4
OSV
firefox vulnerabilities2025-02-11
OSV
CVE-2025-1011: A bug in WebAssembly code generation could have lead to a crash2025-02-04
GHSA
GHSA-qp3j-rxh4-q4h8: A bug in WebAssembly code generation could have lead to a crash2025-02-04
CVEList
A bug in WebAssembly code generation could result in a crash2025-02-04

📋Vendor Advisories

9
Ubuntu
Thunderbird vulnerabilities2025-07-22
Ubuntu
Firefox vulnerabilities2025-02-11
Red Hat
firefox: thunderbird: A bug in WebAssembly code generation could result in a crash2025-02-04
Debian
CVE-2025-1011: firefox - A bug in WebAssembly code generation could have lead to a crash. It may have bee...2025
Microsoft
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem res2022-03-08
CVE-2025-1011 — Code Injection in Mozilla Firefox | cvebase