FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- use-after-free error

Affected packages
firefox < 137.0,2
firefox-esr < 115.22
librewolf < 137.0
thunderbird < 137.0

Details

VuXML ID 28e5f7be-13c8-11f0-a5bd-b42e991fc52e
Discovery 2025-04-01
Entry 2025-04-07

security@mozilla.org reports:

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free.

References

CVE Name CVE-2025-3028
URL https://nvd.nist.gov/vuln/detail/CVE-2025-3028