CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-1937

CVE-2025-1937. CVSS base score 7.5 (HIGH, Source advisory). EPSS 0.00562 (percentile 0.44757), scored 2026-10-04.

Affected technology

firefox · before 115.21.0 (exclusive)
mozilla

firefox · before 128.8.0 (exclusive)
mozilla

firefox · before 135.0 (exclusive)
mozilla

thunderbird · before 128.8.0 (exclusive)
mozilla

thunderbird · from 129.0 (inclusive), before 136.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-1260
CCR priority
30.1 /100 (P4)
CVSS
7.5 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.00562 · percentile 0.44757 · 2026-10-04
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-1937.html