firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access
cve CVE-2025-1932 2 sources, 2 claims · Watch
Red Hat writes:
firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access the claim
firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access the claim
What it is to other things
| affects | mozilla/firefox NVD |
| affects | mozilla/thunderbird NVD |
| made_by | mozilla NVD |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss conflict | NVD | 8.1receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "51A0498A-4BF8-4166-A347-78023C0A6B33",
"versionEndExcluding": "128.8.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
"versionEndExcluding": "136.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "99F8DD82-EEDB-4C5E-9C4A-0F83E492B4CE",
"versionEndExcluding": "128.8.0",
"versionStartIncluding": "]",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "93C81C9D-FC2E-4D7D-A97F-8DB97ED92192",
"versionEndExcluding": "136.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8."
},
{
"lang": "es",
"value": "Un comparador incoherente en xslt/txNodeSorter podría haber dado lugar a un acceso fuera de los límites potencialmente explotable. Solo afecta a la versión 122 y posteriores. Esta vulnerabilidad afecta a Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136 y Thunderbird < 128.8."
}
],
"id": "CVE-2025-1932",
"lastModified": "2026-09-30T19:10:01.007",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1932",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-04T16:05:35.523357Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-03-04T14:15:38.053",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Issue Tracking"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944313"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-16/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-18/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00006.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Cvss cvss conflict | Red Hat | 8.3receipt
What the source handed over{
"CVE": "CVE-2025-1932",
"CWE": "CWE-125",
"advisories": [
"RHSA-2025:2452",
"RHSA-2025:2485",
"RHSA-2025:2486",
"RHSA-2025:2708",
"RHSA-2025:2484",
"RHSA-2025:2481",
"RHSA-2025:2480",
"RHSA-2025:2359",
"RHSA-2025:2699",
"RHSA-2025:2479"
],
"affected_packages": [
"firefox-0:128.8.0-1.el9_2",
"firefox-0:128.8.0-1.el8_2",
"firefox-0:128.8.0-1.el9_0",
"firefox-0:128.8.0-1.el8_6",
"firefox-0:128.8.0-1.el9_5",
"firefox-0:128.8.0-1.el9_4",
"firefox-0:128.8.0-1.el8_4",
"firefox-0:128.8.0-1.el8_10",
"firefox-0:128.8.0-1.el7_9",
"firefox-0:128.8.0-1.el8_8"
],
"bugzilla": "2349796",
"bugzilla_description": "firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access",
"cvss3_score": "8.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-03-04T13:31:23Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-1932.json",
"severity": "important"
} | — |
| Cwe cwe | Red Hat | CWE-125receipt
What the source handed over{
"CVE": "CVE-2025-1932",
"CWE": "CWE-125",
"advisories": [
"RHSA-2025:2452",
"RHSA-2025:2485",
"RHSA-2025:2486",
"RHSA-2025:2708",
"RHSA-2025:2484",
"RHSA-2025:2481",
"RHSA-2025:2480",
"RHSA-2025:2359",
"RHSA-2025:2699",
"RHSA-2025:2479"
],
"affected_packages": [
"firefox-0:128.8.0-1.el9_2",
"firefox-0:128.8.0-1.el8_2",
"firefox-0:128.8.0-1.el9_0",
"firefox-0:128.8.0-1.el8_6",
"firefox-0:128.8.0-1.el9_5",
"firefox-0:128.8.0-1.el9_4",
"firefox-0:128.8.0-1.el8_4",
"firefox-0:128.8.0-1.el8_10",
"firefox-0:128.8.0-1.el7_9",
"firefox-0:128.8.0-1.el8_8"
],
"bugzilla": "2349796",
"bugzilla_description": "firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access",
"cvss3_score": "8.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-03-04T13:31:23Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-1932.json",
"severity": "important"
} | — |
| Packages packages | Red Hat | firefox-0:128.8.0-1.el9_2, firefox-0:128.8.0-1.el8_2, firefox-0:128.8.0-1.el9_0, firefox-0:128.8.0-1.el8_6, firefox-0:128.8.0-1.el9_5, firefox-0:128.8.0-1.el9_4, firefox-0:128.8.0-1.el8_4, firefox-0:128.8.0-1.el8_10, firefox-0:128.8.0-1.el7_9, firefox-0:128.8.0-1.el8_8receipt
What the source handed over{
"CVE": "CVE-2025-1932",
"CWE": "CWE-125",
"advisories": [
"RHSA-2025:2452",
"RHSA-2025:2485",
"RHSA-2025:2486",
"RHSA-2025:2708",
"RHSA-2025:2484",
"RHSA-2025:2481",
"RHSA-2025:2480",
"RHSA-2025:2359",
"RHSA-2025:2699",
"RHSA-2025:2479"
],
"affected_packages": [
"firefox-0:128.8.0-1.el9_2",
"firefox-0:128.8.0-1.el8_2",
"firefox-0:128.8.0-1.el9_0",
"firefox-0:128.8.0-1.el8_6",
"firefox-0:128.8.0-1.el9_5",
"firefox-0:128.8.0-1.el9_4",
"firefox-0:128.8.0-1.el8_4",
"firefox-0:128.8.0-1.el8_10",
"firefox-0:128.8.0-1.el7_9",
"firefox-0:128.8.0-1.el8_8"
],
"bugzilla": "2349796",
"bugzilla_description": "firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access",
"cvss3_score": "8.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-03-04T13:31:23Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-1932.json",
"severity": "important"
} | — |
| Product product | NVD | Firefoxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "51A0498A-4BF8-4166-A347-78023C0A6B33",
"versionEndExcluding": "128.8.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
"versionEndExcluding": "136.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "99F8DD82-EEDB-4C5E-9C4A-0F83E492B4CE",
"versionEndExcluding": "128.8.0",
"versionStartIncluding": "]",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "93C81C9D-FC2E-4D7D-A97F-8DB97ED92192",
"versionEndExcluding": "136.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8."
},
{
"lang": "es",
"value": "Un comparador incoherente en xslt/txNodeSorter podría haber dado lugar a un acceso fuera de los límites potencialmente explotable. Solo afecta a la versión 122 y posteriores. Esta vulnerabilidad afecta a Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136 y Thunderbird < 128.8."
}
],
"id": "CVE-2025-1932",
"lastModified": "2026-09-30T19:10:01.007",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1932",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-04T16:05:35.523357Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-03-04T14:15:38.053",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Issue Tracking"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944313"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-16/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-18/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00006.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2025-1932",
"CWE": "CWE-125",
"advisories": [
"RHSA-2025:2452",
"RHSA-2025:2485",
"RHSA-2025:2486",
"RHSA-2025:2708",
"RHSA-2025:2484",
"RHSA-2025:2481",
"RHSA-2025:2480",
"RHSA-2025:2359",
"RHSA-2025:2699",
"RHSA-2025:2479"
],
"affected_packages": [
"firefox-0:128.8.0-1.el9_2",
"firefox-0:128.8.0-1.el8_2",
"firefox-0:128.8.0-1.el9_0",
"firefox-0:128.8.0-1.el8_6",
"firefox-0:128.8.0-1.el9_5",
"firefox-0:128.8.0-1.el9_4",
"firefox-0:128.8.0-1.el8_4",
"firefox-0:128.8.0-1.el8_10",
"firefox-0:128.8.0-1.el7_9",
"firefox-0:128.8.0-1.el8_8"
],
"bugzilla": "2349796",
"bugzilla_description": "firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access",
"cvss3_score": "8.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-03-04T13:31:23Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-1932.json",
"severity": "important"
} | high |
| Status status | NVD | Modifiedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "51A0498A-4BF8-4166-A347-78023C0A6B33",
"versionEndExcluding": "128.8.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
"versionEndExcluding": "136.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "99F8DD82-EEDB-4C5E-9C4A-0F83E492B4CE",
"versionEndExcluding": "128.8.0",
"versionStartIncluding": "]",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "93C81C9D-FC2E-4D7D-A97F-8DB97ED92192",
"versionEndExcluding": "136.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8."
},
{
"lang": "es",
"value": "Un comparador incoherente en xslt/txNodeSorter podría haber dado lugar a un acceso fuera de los límites potencialmente explotable. Solo afecta a la versión 122 y posteriores. Esta vulnerabilidad afecta a Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136 y Thunderbird < 128.8."
}
],
"id": "CVE-2025-1932",
"lastModified": "2026-09-30T19:10:01.007",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1932",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-04T16:05:35.523357Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-03-04T14:15:38.053",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Issue Tracking"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944313"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-16/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-18/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00006.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | Mozillareceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.8",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "136",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "51A0498A-4BF8-4166-A347-78023C0A6B33",
"versionEndExcluding": "128.8.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
"versionEndExcluding": "136.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "99F8DD82-EEDB-4C5E-9C4A-0F83E492B4CE",
"versionEndExcluding": "128.8.0",
"versionStartIncluding": "]",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "93C81C9D-FC2E-4D7D-A97F-8DB97ED92192",
"versionEndExcluding": "136.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8."
},
{
"lang": "es",
"value": "Un comparador incoherente en xslt/txNodeSorter podría haber dado lugar a un acceso fuera de los límites potencialmente explotable. Solo afecta a la versión 122 y posteriores. Esta vulnerabilidad afecta a Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136 y Thunderbird < 128.8."
}
],
"id": "CVE-2025-1932",
"lastModified": "2026-09-30T19:10:01.007",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1932",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-04T16:05:35.523357Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-03-04T14:15:38.053",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Issue Tracking"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944313"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-16/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-18/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00006.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access zetlyn/cve-redhat · 2025-03-04 | cvss 8.3 cwe CWE-125 packages firefox-0:128.8.0-1.el9_2, firefox-0:128.8.0-1.el8_2, firefox-0:128.8.0-1.el9_0, firefox-0:128.8.0-1.el8_6, firefox-0:128.8.0-1.el9_5, firefox-0:128.8.0-1.el9_4, firefox-0:128.8.0-1.el8_4, firefox-0:128.8.0-1.el8_10, firefox-0:128.8.0-1.el7_9, firefox-0:128.8.0-1.el8_8 severity important | source |
| An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8. zetlyn/cve-nvd · 2025-03-04 | cvss 8.1 product Firefox status Modified vendor Mozilla | source |