8.8

CVE-2025-1014

Certificate length was not properly checked

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox SwEdition esr Version < 128.7.0
Mozilla ≫ Firefox SwEdition - Version < 135.0
Mozilla ≫ Thunderbird SwEdition esr Version >= 128.0.1 < 128.7.0
Mozilla ≫ Thunderbird SwEdition - Version >= 131.0 < 135.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://www.mozilla.org/security/advisories/mfsa2025-09/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2025-10/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2025-11/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2025-07/
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1940804
Permissions Required
https://lists.debian.org/debian-lts-announce/2025/02/msg00006.html