Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.
History

Tue, 29 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-04-29T13:13:48.089Z

Updated: 2025-04-29T15:37:05.713Z

Reserved: 2025-04-29T13:13:47.408Z

Link: CVE-2025-4091

cve-icon Vulnrichment

Updated: 2025-04-29T15:37:00.605Z

cve-icon NVD

Status : Received

Published: 2025-04-29T14:15:35.717

Modified: 2025-04-29T16:15:39.570

Link: CVE-2025-4091

cve-icon Redhat

No data.