{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-14T22:20:37.926","vulnerabilities":[{"cve":{"id":"CVE-2025-1014","sourceIdentifier":"security@mozilla.org","published":"2025-02-04T14:15:32.237","lastModified":"2026-04-13T15:16:50.083","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135."},{"lang":"es","value":"La longitud del certificado no se comprobaba correctamente al añadirlo a un almacén de certificados. En la práctica, solo se procesaban los datos de confianza. Esta vulnerabilidad afecta a Firefox &lt; 135, Firefox ESR &lt; 128.7, Thunderbird &lt; 128.7 y Thunderbird &lt; 135."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*","versionEndExcluding":"128.7.0","matchCriteriaId":"B1B11C09-3033-44F5-ACC7-591196075CB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*","versionEndExcluding":"135.0","matchCriteriaId":"C08017D5-BBC7-4E01-92D2-CE2E2ED9453A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*","versionStartIncluding":"128.0.1","versionEndExcluding":"128.7.0","matchCriteriaId":"0504330C-A82A-4E1E-9774-38CCB3DF8D92"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*","versionStartIncluding":"131.0","versionEndExcluding":"135.0","matchCriteriaId":"B5DC3260-2056-4C30-BCBA-AD45537FF0F5"}]}]}],"references":[{"url":"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1940804","source":"security@mozilla.org","tags":["Permissions Required"]},{"url":"https:\/\/www.mozilla.org\/security\/advisories\/mfsa2025-07\/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https:\/\/www.mozilla.org\/security\/advisories\/mfsa2025-09\/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https:\/\/www.mozilla.org\/security\/advisories\/mfsa2025-10\/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https:\/\/www.mozilla.org\/security\/advisories\/mfsa2025-11\/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https:\/\/lists.debian.org\/debian-lts-announce\/2025\/02\/msg00006.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}