Memory Safety Vulnerabilities in Firefox and Thunderbird by Mozilla
CVE-2025-1937

7.5HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
4 March 2025

What is CVE-2025-1937?

This vulnerability encompasses critical memory safety flaws found in specific versions of Firefox and Thunderbird. These flaws involve memory corruption issues that, if successfully exploited, could potentially allow an attacker to execute arbitrary code. These security defects affect main releases and extended support versions of Firefox and Thunderbird, necessitating prompt updates to the latest versions to mitigate risks.

Affected Version(s)

Firefox < 136

Firefox ESR < 115.21

Firefox ESR < 128.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

the Mozilla Fuzzing Team, Andrew McCreight
.
CVE-2025-1937 : Memory Safety Vulnerabilities in Firefox and Thunderbird by Mozilla