Memory Safety Vulnerabilities in Firefox and Thunderbird Products by Mozilla
CVE-2025-5268

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
27 May 2025

What is CVE-2025-5268?

Memory safety bugs were found in specific versions of Firefox and Thunderbird, indicating potential memory corruption issues. With sufficient effort, these vulnerabilities could be exploited to execute arbitrary code. This affects users on Firefox versions prior to 139 and Firefox ESR versions prior to 128.11. Mozilla has addressed these vulnerabilities in the latest releases, providing critical updates for enhanced security.

Affected Version(s)

Firefox < 139

Firefox ESR < 128.11

Thunderbird < 139

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

the Mozilla Fuzzing Team, Masayuki Nakano
.
CVE-2025-5268 : Memory Safety Vulnerabilities in Firefox and Thunderbird Products by Mozilla