CVE-2025-1014
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was process
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
HIGH · CVSS 8.8
EPSS 0.00212
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0