Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
ID: 165e45d1-283b-52ea-935d-400427d095a0
STIX ID: report--165e45d1-283b-52ea-935d-400427d095a0
Feed Name: CISecurity.org Advisories
**Executive Summary:** Multiple vulnerabilities were disclosed and fixed in Mozilla Firefox and Thunderbird (including ESR), most notably a use-after-free in XSLTProcessor (CVE-2025-3028) that could allow arbitrary code execution via drive-by compromise; several memory safety bugs (CVE-2025-3030, CVE-2025-3034) and additional lower-severity issues (CVE-2025-3031, CVE-2025-3032, CVE-2025-3029, CVE-2025-3035, CVE-2025-3033) were also addressed. Successful exploitation could let an attacker install programs, view/change/delete data, or create accounts depending on user privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
