← back
CVE-2025-45663mediumCWE-244

CVE-2025-45663

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
In short

NetSurf v3.11 reads uninitialized memory from the heap when creating a dom_event structure, potentially exposing sensitive data from other parts of the application's memory.

Technical detail

CWE-244: Improper Clearing of Heap Memory Before Release. When NetSurf constructs dom_event structures, heap memory is accessed without proper initialization, allowing information disclosure of previous heap contents. This occurs during normal DOM event creation without requiring special user interaction.

Summary generated and translated by AI from the official description.
An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected products
n/a · n/a