Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 28 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
Wed, 23 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mozilla
Mozilla firefox Mozilla firefox Esr Mozilla thunderbird Mozilla thunderbird Esr |
|
Vendors & Products |
Mozilla
Mozilla firefox Mozilla firefox Esr Mozilla thunderbird Mozilla thunderbird Esr |
Wed, 23 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-119 | |
Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. | |
References |
|
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-07-22T20:49:28.310Z
Updated: 2025-07-24T03:55:31.276Z
Reserved: 2025-07-22T10:14:10.587Z
Link: CVE-2025-8040

Updated: 2025-07-23T15:08:56.301Z

Status : Analyzed
Published: 2025-07-22T21:15:51.163
Modified: 2025-07-28T14:00:29.940
Link: CVE-2025-8040
