FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- use-after-free while parsing JSON

Affected packages
firefox < 134.0,2
librewolf < 134.0
firefox-esr < 128.6.0
thunderbird < 134.0

Details

VuXML ID f1f92cd3-116c-11f0-8b2c-b42e991fc52e
Discovery 2025-01-07
Entry 2025-04-04

security@mozilla.org reports:

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free.

References

CVE Name CVE-2025-0240
URL https://nvd.nist.gov/vuln/detail/CVE-2025-0240