vulnerability

SUSE: CVE-2025-3028: SUSE Linux Security Advisory

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
Published
Apr 1, 2025
Added
Apr 3, 2025
Modified
Nov 4, 2025

Description

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

Solutions

suse-upgrade-libmozjs-128-0suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-othersuse-upgrade-mozjs128suse-upgrade-mozjs128-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.