- Description
- Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.
- Source
- security@mozilla.org
- NVD status
- Analyzed
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 2.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-119
- Hype score
- Not currently trending
⚠️Actualizaciones de seguridad para los productos de Mozilla ❗CVE-2025-2817 ❗CVE-2025-4092 ❗CVE-2025-4093 ❗CVE-2025-4082 ❗CVE-2025-4083 ➡️Más info: https://t.co/JJi9oHSZKG https://t.co/FTPvTHCUWL
@CERTpy
30 Apr 2025
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-4092 Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of th… https://t.co/hGRUvZaGTM
@CVEnew
29 Apr 2025
188 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
"versionEndExcluding": "138.0"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1E8CCF1-4E91-44CC-A652-B23D1337A485",
"versionEndExcluding": "138.0"
}
],
"operator": "OR"
}
]
}
]