CVE-2025-45663
Published Nov 3, 2025An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
Vendor/product archive
4 CVEs tagged to netsurf-browser / netsurf — 0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.
An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.
An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.