PT-2025-33870 · Mozilla+5 · Thunderbird+8

Paul Bone

+1

·

Published

2025-08-19

·

Updated

2026-02-02

·

CVE-2025-9184

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 142 Firefox ESR versions prior to 140.2 Thunderbird versions prior to 142 Thunderbird ESR versions prior to 140.2
Description: Memory safety bugs are present in the software, with some showing evidence of memory corruption. It is presumed that, with sufficient effort, some of these bugs could be exploited to run arbitrary code.
Recommendations: Update Firefox to version 142 or later. Update Firefox ESR to version 140.2 or later. Update Thunderbird to version 142 or later. Update Thunderbird ESR to version 140.2 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-12559
ALT-PU-2025-12562
ALT-PU-2025-14599
BDU:2025-10502
CVE-2025-9184
OPENSUSE-SU-2025:15467-1
OPENSUSE-SU-2025:15472-1
OPENSUSE-SU-2025:15516-1
SUSE-SU-2025:03007-1
SUSE-SU-2025:03008-1
SUSE-SU-2025:03009-1
SUSE-SU-2025_03008-1
SUSE-SU-2025_03009-1
USN-7991-1

Affected Products

Alt Linux
Astra Linux
Firefox
Firefox Esr
Linuxmint
Suse
Thunderbird
Thunderbird Esr
Ubuntu