Memory Safety Vulnerability in Firefox ESR and Thunderbird by Mozilla
CVE-2025-5269

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
27 May 2025

What is CVE-2025-5269?

A memory safety issue has been identified in Firefox ESR 128.10 and Thunderbird 128.10, which indicates signs of memory corruption. This flaw poses a risk that could potentially allow an attacker to execute arbitrary code through carefully crafted inputs. Users are urged to update to Firefox ESR and Thunderbird versions 128.11 or higher, where this vulnerability has been addressed.

Affected Version(s)

Firefox ESR < 128.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Randell Jesup
.
The Cyber Security Vulnerability Database.