CVE-2025-1942 — Use of Uninitialized Resource in Mozilla Firefox
CWE-908 — Use of Uninitialized ResourceCWE-824 — Access of Uninitialized Pointer11 documents8 sources
Severity
9.8CRITICALNVD
OSV7.5
EPSS
0.5%
top 35.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4
Latest updateFeb 2
Description
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9