CVE Vulnerabilities

CVE-2025-45663

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Nov 03, 2025 | Modified: Nov 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

Name Vendor Start Version End Version
Netsurf Netsurf-browser 3.11 (including) 3.11 (including)

References