Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7444 | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136. |
Ubuntu USN |
USN-7334-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-7991-1 | Thunderbird vulnerabilities |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136. | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136. |
| Title | firefox: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer | Disclosure of uninitialized memory when .toUpperCase() causes string to get longer |
Fri, 28 Mar 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox Mozilla thunderbird |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mozilla
Mozilla firefox Mozilla thunderbird |
Tue, 25 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-908 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 12 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-908 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 05 Mar 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer | |
| Weaknesses | CWE-824 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 05 Mar 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136. | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136. |
| References |
|
Tue, 04 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-908 | |
| Metrics |
cvssV3_1
|
Tue, 04 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:30:28.192Z
Reserved: 2025-03-04T12:29:51.191Z
Link: CVE-2025-1942
Updated: 2025-03-04T15:45:14.531Z
Status : Modified
Published: 2025-03-04T14:15:39.167
Modified: 2026-04-13T15:16:53.940
Link: CVE-2025-1942
OpenCVE Enrichment
Updated: 2026-04-20T18:30:13Z
EUVD
Ubuntu USN