← Back

CVE-2025-4215

nvd nist
Published: May 2, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.3
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.63.3b17 is able to address this issue. The patch is identified as eaedaf5b10d2f7857c6b77fbf7d4a80681d4d46c. It is recommended to upgrade the affected component.

Affected (18)

1 product
Ublock Origin
1 product
Debian Linux
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Ublockorigin
Before 1.63.3
Version 1.63.3 beta10
Version 1.63.3 beta11
Version 1.63.3 beta12
Version 1.63.3 beta13
Version 1.63.3 beta14
Version 1.63.3 beta15
Version 1.63.3 beta16
Version 1.63.3 beta1
Version 1.63.3 beta2
Version 1.63.3 beta3
Version 1.63.3 beta4
Version 1.63.3 beta5
Version 1.63.3 beta6
Version 1.63.3 beta7
Version 1.63.3 beta8
Version 1.63.3 beta9
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

References (7)

Source: cna@vuldb.com
Permissions RequiredVDB Entry
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitPatch

Timeline

No history available yet.