Memory Safety Bugs in Firefox and Thunderbird Affecting Multiple Versions
CVE-2025-1016
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 4 February 2025
What is CVE-2025-1016?
Memory safety vulnerabilities have been identified in Firefox and Thunderbird that may allow attackers to exploit memory corruption issues. These flaws exist in versions before Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, and corresponding Thunderbird versions. If successfully exploited, these vulnerabilities could potentially lead to arbitrary code execution, posing a significant risk to user security. Users are advised to update their software to the latest versions to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 135
Firefox ESR < 115.20
Firefox ESR < 128.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved