Memory Safety Flaw in Firefox ESR and Thunderbird by Mozilla
CVE-2025-4093
6.5MEDIUM
What is CVE-2025-4093?
A memory safety issue has been identified in the Firefox Extended Support Release (ESR) 128.9 and Thunderbird 128.9. This vulnerability manifests as memory corruption, which, if leveraged effectively, could allow an attacker to execute arbitrary code on affected systems. Users are advised to upgrade to Firefox ESR version 128.10 or later, and Thunderbird ESR version 128.10 or later, to mitigate potential risks associated with this flaw. It's crucial to maintain up-to-date software to ensure safeguards against such vulnerabilities.
Affected Version(s)
Firefox ESR < 128.10
Thunderbird < 128.10
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew McCreight