Published December 9, 2025
Severity CRITICAL
CNA Score 9.8
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
- cpe:2.3:a:mozilla:firefox_esr
- cpe:2.3:a:mozilla:firefox
Sources
AlmaLinux Security Advisory
AlmaLinux 8 Severity HIGHHas FixAdded at: Dec 12, 2025
AlmaLinux 9 Severity HIGHHas FixAdded at: Dec 12, 2025
Debian Security Tracker
Debian 11, 12, 13 Severity CRITICALHas FixAdded at: Dec 09, 2025
Debian 14 Severity CRITICALNo FixAdded at: Dec 09, 2025
Echo
Echo Severity CRITICALHas FixAdded at: Dec 09, 2025
Homebrew
Homebrew Severity CRITICALHas FixAdded at: Dec 12, 2025
Nix
Nix Severity CRITICALHas FixAdded at: Dec 12, 2025
Red Hat Errata
Red Hat 6, 7 Severity MEDIUMNo FixAdded at: Dec 10, 2025
Red Hat 8 Severity MEDIUMHas FixAdded at: Dec 10, 2025
Red Hat 9 Severity MEDIUMHas FixAdded at: Dec 10, 2025
Red Hat 10 Severity MEDIUMHas FixAdded at: Dec 10, 2025
Rocky Linux Product Errata
Rocky 8 Severity HIGHHas FixAdded at: Dec 14, 2025
Rocky 9 Severity HIGHHas FixAdded at: Dec 14, 2025
Rocky 10 Severity HIGHHas FixAdded at: Dec 14, 2025
Ubuntu Security Tracker
Ubuntu 22.04 Severity MEDIUMNo FixAdded at: Dec 11, 2025
VulnCheck NVD++
Linux Severity CRITICALHas FixAdded at: Dec 10, 2025
Windows Severity CRITICALHas FixAdded at: Dec 10, 2025
NVD
Linux Severity CRITICALHas FixAdded at: Dec 12, 2025
Windows Severity CRITICALHas FixAdded at: Dec 12, 2025