CVE-2025-1942
published 2025-03-04CVE-2025-1942: When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 136.0-1 (sid) | firefox 136.0-1 (sid) |
| mozilla | firefox | < 136.0 | 136.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 136.0+build3-0ubuntu0.20.04.1 | 136.0+build3-0ubuntu0.20.04.1 |
| mozilla | thunderbird | < 136.0 | 136.0 |
| mozilla | thunderbird | >= 0 < 1:140.7.1+build1-0ubuntu0.22.04.1 | 1:140.7.1+build1-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL