CVE-2025-1933
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Vendor
Product
CWE
Yayın Tarihi
2025-03-04 14:15:38
Güncelleme
2025-11-03 21:18:53
Source Identifier
security@mozilla.org
KEV Date Added
-
Kategoriler
Referanslar
https://bugzilla.mozilla.org/show_bug.cgi?id=1946004
https://www.mozilla.org/security/advisories/mfsa2025-14/
https://www.mozilla.org/security/advisories/mfsa2025-15/
https://www.mozilla.org/security/advisories/mfsa2025-16/
https://www.mozilla.org/security/advisories/mfsa2025-17/
https://www.mozilla.org/security/advisories/mfsa2025-18/
https://lists.debian.org/debian-lts-announce/2025/03/msg00006.html