Uninitialized Memory Vulnerability in Firefox and Thunderbird by Mozilla
CVE-2025-9181

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 August 2025

What is CVE-2025-9181?

This vulnerability is related to uninitialized memory within the JavaScript Engine component of Firefox and Thunderbird. Affected versions include Firefox versions prior to 142, and Thunderbird versions before 142. The flaw may allow attackers to exploit uninitialized memory, potentially leading to information leaks or arbitrary code execution. Users are advised to update their software to mitigate the risks associated with this vulnerability.

Affected Version(s)

Firefox < 142

Firefox ESR < 128.14

Firefox ESR < 140.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Irvan Kurniawan
.