logo

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution

ID: 165e45d1-283b-52ea-935d-400427d095a0

STIX ID: report--165e45d1-283b-52ea-935d-400427d095a0

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-04-03

Date Updated: 2026-04-27

...
...

**Executive Summary:** Multiple vulnerabilities were disclosed and fixed in Mozilla Firefox and Thunderbird (including ESR), most notably a use-after-free in XSLTProcessor (CVE-2025-3028) that could allow arbitrary code execution via drive-by compromise; several memory safety bugs (CVE-2025-3030, CVE-2025-3034) and additional lower-severity issues (CVE-2025-3031, CVE-2025-3032, CVE-2025-3029, CVE-2025-3035, CVE-2025-3033) were also addressed. Successful exploitation could let an attacker install programs, view/change/delete data, or create accounts depending on user privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.