CVE-2025-1011

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

History

No history.

Information

Published : 2025-02-04 14:15

Updated : 2026-06-17 08:38


NVD link : CVE-2025-1011

Mitre link : CVE-2025-1011

CVE.ORG link : CVE-2025-1011


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')