CVE-2025-3032
HIGHDescription
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
Is your site exposed to CVE-2025-3032?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | thunderbird |
References
Frequently Asked Questions
What is CVE-2025-3032? +
How severe is CVE-2025-3032? +
What products are affected by CVE-2025-3032? +
How do I check if I'm vulnerable to CVE-2025-3032? +
Related Vulnerabilities
Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN …
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit …
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP …
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 …
When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. …
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised …