Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.
History

Thu, 01 May 2025 02:45:00 +0000

Type Values Removed Values Added
Title firefox: thunderbird: Memory safety bugs fixed in Firefox 138 and Thunderbird 138
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 29 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-04-29T13:13:49.479Z

Updated: 2025-04-29T15:36:14.382Z

Reserved: 2025-04-29T13:13:48.785Z

Link: CVE-2025-4092

cve-icon Vulnrichment

Updated: 2025-04-29T15:36:07.217Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-29T14:15:35.820

Modified: 2025-05-02T13:53:40.163

Link: CVE-2025-4092

cve-icon Redhat

Severity : Important

Publid Date: 2025-04-29T13:13:49Z

Links: CVE-2025-4092 - Bugzilla