Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3608

Опубликовано: 15 апр. 2025
Источник: redhat
CVSS3: 7.5

Описание

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory: A race condition exists in nsHttpTransaction that can be exploited to cause memory corruption, leading to an exploitable condition.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9firefox-flatpak-containerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-364
https://bugzilla.redhat.com/show_bug.cgi?id=2359752firefox: Race condition in nsHttpTransaction could lead to memory corruption

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.

CVSS3: 6.5
nvd
2 месяца назад

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.

CVSS3: 6.5
debian
2 месяца назад

A race condition existed in nsHttpTransaction that could have been exp ...

CVSS3: 6.5
github
2 месяца назад

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.

CVSS3: 5
fstec
2 месяца назад

Уязвимость почтового клиента Thunderbird, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю выполнить произвольный код

7.5 High

CVSS3