Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.
History

Tue, 29 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-04-29T13:13:49.479Z

Updated: 2025-04-29T15:36:14.382Z

Reserved: 2025-04-29T13:13:48.785Z

Link: CVE-2025-4092

cve-icon Vulnrichment

Updated: 2025-04-29T15:36:07.217Z

cve-icon NVD

Status : Received

Published: 2025-04-29T14:15:35.820

Modified: 2025-04-29T16:15:39.707

Link: CVE-2025-4092

cve-icon Redhat

No data.