NVD Vulnerability Detail
Search Exploit, PoC
CVE-2025-1010
Summary

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

Summary

Un atacante podría haber provocado un Use-after-free a través de la API de resaltado personalizado, lo que habría provocado un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7 y Thunderbird < 135.

Publication Date Feb. 4, 2025, 11:15 p.m.
Registration Date Feb. 5, 2025, 4 a.m.
Last Update April 14, 2026, 12:16 a.m.
CVSS3.1 : CRITICAL
スコア 9.8
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR) 不要
利用者の関与(UI) 不要
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 115.20.0
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* 135.0
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 128.1.0 128.7.0
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* 128.0.1 128.7.0
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* 131.0 135.0
Related information, measures and tools
Common Vulnerabilities List