Vulnerability Description
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 136.0 |
| Mozilla | Thunderbird | < 136.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1947139Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2025-14/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-17/Vendor Advisory
FAQ
What is CVE-2025-1942?
CVE-2025-1942 is a vulnerability with a CVSS score of 9.8 (CRITICAL). When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird ...
How severe is CVE-2025-1942?
CVE-2025-1942 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-1942?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Thunderbird.