Memory Safety Vulnerabilities in Firefox and Thunderbird Products
CVE-2025-3030

8.1HIGH

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
1 April 2025

Summary

Recent investigations have uncovered memory safety bugs in multiple versions of Firefox and Thunderbird, including Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird ESR 128.8. These vulnerabilities indicate evidence of memory corruption, raising concerns that under specific conditions, they could be exploited to execute arbitrary code on the affected systems. Users should ensure their software is updated to Firefox 137, Thunderbird 137, Firefox ESR 128.9, or Thunderbird ESR 128.9 to mitigate these risks.

Affected Version(s)

Firefox < 137

Firefox ESR < 128.9

Thunderbird < 137

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sylvestre Ledru, Paul Bone and the Mozilla Fuzzing Team
.