CVE-2025-1011

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. (en) A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

03 Nov 2025, 21:18

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00005.html -
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00006.html -

06 Feb 2025, 19:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.8
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1936454 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1936454 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-07/ - () https://www.mozilla.org/security/advisories/mfsa2025-07/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-09/ - () https://www.mozilla.org/security/advisories/mfsa2025-09/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-10/ - () https://www.mozilla.org/security/advisories/mfsa2025-10/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-11/ - () https://www.mozilla.org/security/advisories/mfsa2025-11/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
First Time Mozilla
Mozilla firefox
Mozilla thunderbird
CWE NVD-CWE-noinfo

05 Feb 2025, 19:15

Type Values Removed Values Added
Summary
  • (es) Un error en la generación de código de WebAssembly podría haber provocado un bloqueo. Es posible que un atacante haya podido aprovecharlo para ejecutar el código. Esta vulnerabilidad afecta a Firefox &lt; 135, Firefox ESR &lt; 128.7, Thunderbird &lt; 128.7 y Thunderbird &lt; 135.
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

04 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-04 14:15

Updated : 2026-04-13 15:16


NVD link : CVE-2025-1011

Mitre link : CVE-2025-1011

CVE.ORG link : CVE-2025-1011


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')