CVE-2025-1011 — Code Injection in Mozilla Firefox
Severity
8.8HIGHNVD
OSV9.8
EPSS
0.2%
top 56.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateJul 22
Description
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
4GHSA
▶
📋Vendor Advisories
9Red Hat
▶
Debian▶
CVE-2025-1011: firefox - A bug in WebAssembly code generation could have lead to a crash. It may have bee...↗2025
Microsoft▶
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem res↗2022-03-08