Memory Safety Flaw in Firefox ESR and Thunderbird by Mozilla
CVE-2025-4093

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
29 April 2025

What is CVE-2025-4093?

A memory safety issue has been identified in the Firefox Extended Support Release (ESR) 128.9 and Thunderbird 128.9. This vulnerability manifests as memory corruption, which, if leveraged effectively, could allow an attacker to execute arbitrary code on affected systems. Users are advised to upgrade to Firefox ESR version 128.10 or later, and Thunderbird ESR version 128.10 or later, to mitigate potential risks associated with this flaw. It's crucial to maintain up-to-date software to ensure safeguards against such vulnerabilities.

Affected Version(s)

Firefox ESR < 128.10

Thunderbird < 128.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew McCreight
.
CVE-2025-4093 : Memory Safety Flaw in Firefox ESR and Thunderbird by Mozilla