216.73.216.197

CVE-2025-0242

· Published 07/01/2025 16:15 · Modified 03/04/2025 16:30

Labels: CVE-2025-0242 2025-01-07CVE-2025-0242CWE-787[email protected]

Essential information

Published
07/01/2025 16:15
Modified
03/04/2025 16:30
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and Thunderbird < 128.6.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla / thunderbird cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozilla / thunderbird cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

References