Memory Safety Bugs in Firefox and Thunderbird Affecting Multiple Versions
CVE-2025-1016

Currently unrated

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
4 February 2025

Summary

Memory safety vulnerabilities have been identified in Firefox and Thunderbird that may allow attackers to exploit memory corruption issues. These flaws exist in versions before Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, and corresponding Thunderbird versions. If successfully exploited, these vulnerabilities could potentially lead to arbitrary code execution, posing a significant risk to user security. Users are advised to update their software to the latest versions to mitigate these risks.

Affected Version(s)

Firefox < 135

Firefox ESR < 115.20

Firefox ESR < 128.7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew McCreight, Randell Jesup, Andrew Osmond, Akmat Suleimanov and the Mozilla Fuzzing Team
.