6.5

CVE-2025-45663

Exploit
An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netsurf-browser ≫ Netsurf Version 3.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.271
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-244 Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

https://github.com/Fysac/netsurf-disclosure/tree/main/CVE-2025-45663
Third Party Advisory
Exploit
https://www.netsurf-browser.org/
Product