Out-of-Bounds Read or Write Vulnerability in Firefox ESR by Mozilla
CVE-2025-4919

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
17 May 2025

Badges

📈 Score: 616👾 Exploit Exists📰 News Worthy

What is CVE-2025-4919?

CVE-2025-4919 is a vulnerability identified in Mozilla's Firefox and Thunderbird applications, specifically impacting versions below 138.0.4 for Firefox, below 128.10.1 and 115.23.1 for Firefox ESR, and below 128.10.2 and 138.0.2 for Thunderbird. This flaw results from an out-of-bounds read or write condition that can occur when an attacker confuses the sizes of array indices within JavaScript objects. Such a vulnerability can lead to unauthorized memory access, which may result in application crashes or allow attackers to execute arbitrary code. This poses a significant threat to organizations as it can compromise system integrity and security, potentially giving attackers control over sensitive data and applications.

Potential Impact of CVE-2025-4919

  1. Arbitrary Code Execution: Exploitation of this vulnerability can allow attackers to execute arbitrary code within the context of the affected applications, leading to unauthorized actions and access within the organization's IT infrastructure.

  2. Data Exfiltration: With the capability to manipulate memory and potentially gain access to sensitive data, this vulnerability poses a risk of data breaches, allowing attackers to extract confidential information from the affected applications.

  3. Service Disruption: By leveraging this vulnerability, attackers can cause crashes or instability in the browser or email client, disrupting services and workflows for users. This can result in reduced productivity and increased operational risks for the organization.

Affected Version(s)

Firefox < 138.0.4

Firefox ESR < 128.10.1

Firefox ESR < 115.23.1

News Articles

Critical Firefox 0-Day Flaws Allow Remote Code Execution

Mozilla has urgently patched two critical 0-day vulnerabilities in its popular web browser Firefox, both of which could allow remote attackers.

6 days ago

Firefox 0-day Vulnerabilities Let Attackers Execute Malicious Code

Mozilla has released an emergency security update to address two critical vulnerabilities in Firefox that could allow attackers.

6 days ago

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by CybersecurityNews

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manfred Paul working with Trend Micro's Zero Day Initiative
.
CVE-2025-4919 : Out-of-Bounds Read or Write Vulnerability in Firefox ESR by Mozilla