Memory Safety Vulnerabilities in Firefox and Thunderbird Products
CVE-2025-3030
8.1HIGH
Summary
Recent investigations have uncovered memory safety bugs in multiple versions of Firefox and Thunderbird, including Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird ESR 128.8. These vulnerabilities indicate evidence of memory corruption, raising concerns that under specific conditions, they could be exploited to execute arbitrary code on the affected systems. Users should ensure their software is updated to Firefox 137, Thunderbird 137, Firefox ESR 128.9, or Thunderbird ESR 128.9 to mitigate these risks.
Affected Version(s)
Firefox < 137
Firefox ESR < 128.9
Thunderbird < 137
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sylvestre Ledru, Paul Bone and the Mozilla Fuzzing Team