PT-2025-3812 · Mozilla+4 · Thunderbird+5

Akmat Suleimanov

+2

·

Published

2025-01-07

·

Updated

2026-04-13

·

CVE-2025-0247

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 134.0.2 Firefox ESR versions prior to 140.4.0 Thunderbird versions prior to 138.0 Thunderbird versions prior to 137.0
Description The software is affected by memory safety flaws that could allow for arbitrary code execution. These flaws may lead to memory corruption, potentially enabling an attacker to exploit the system by tricking a user into opening a specially crafted website. No information is available regarding the number of potentially affected devices or real-world incidents. The issue involves a failure to properly validate buffer sizes during data copying operations.
Recommendations Update Firefox to version 134.0.2 or later. Update Firefox ESR to version 140.4.0 or later. Update Thunderbird to version 138.0 or later. Update Thunderbird to version 137.0 or later.

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-14599
ALT-PU-2025-1984
ALT-PU-2025-2230
ALT-PU-2025-5137
ALT-PU-2025-7695
BDU:2025-02406
CVE-2025-0247
OPENSUSE-SU-2025:14630-1
USN-7191-1
USN-7991-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Thunderbird
Ubuntu