CVE-2025-1933

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

03 Apr 2025, 13:29

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1946004 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1946004 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2025-14/ - () https://www.mozilla.org/security/advisories/mfsa2025-14/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-15/ - () https://www.mozilla.org/security/advisories/mfsa2025-15/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-16/ - () https://www.mozilla.org/security/advisories/mfsa2025-16/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-17/ - () https://www.mozilla.org/security/advisories/mfsa2025-17/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-18/ - () https://www.mozilla.org/security/advisories/mfsa2025-18/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla thunderbird
Mozilla
CWE NVD-CWE-noinfo

25 Mar 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

12 Mar 2025, 17:15

Type Values Removed Values Added
CWE CWE-252
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : unknown
Summary
  • (es) En las CPU de 64 bits, cuando el JIT compila los valores de retorno de WASM i32, estos pueden tomar bits de la memoria restante. Esto puede provocar que se los trate como un tipo diferente. Esta vulnerabilidad afecta a Firefox &lt; 136, Firefox ESR &lt; 115.21, Firefox ESR &lt; 128.8, Thunderbird &lt; 136 y Thunderbird &lt; 128.8.

05 Mar 2025, 00:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2025-17/ -
  • () https://www.mozilla.org/security/advisories/mfsa2025-18/ -
Summary (en) On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8. (en) On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

04 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-252
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

04 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 14:15

Updated : 2025-04-03 13:29


NVD link : CVE-2025-1933

Mitre link : CVE-2025-1933

CVE.ORG link : CVE-2025-1933


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox