Metrics
Affected Vendors & Products
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Thu, 03 Apr 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Mozilla
         Mozilla firefox Mozilla thunderbird  | 
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Mozilla
         Mozilla firefox Mozilla thunderbird  | 
Fri, 14 Mar 2025 03:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat rhel Els
         | 
|
| CPEs | cpe:/a:redhat:rhel_aus:8.2 cpe:/o:redhat:rhel_els:7  | 
|
| Vendors & Products | 
        
        Redhat rhel Els
         | 
Mon, 10 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat rhel Aus
         Redhat rhel E4s Redhat rhel Eus Redhat rhel Tus  | 
|
| CPEs | cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_aus:8.6 cpe:/a:redhat:rhel_e4s:8.4 cpe:/a:redhat:rhel_e4s:8.6 cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_eus:8.8 cpe:/a:redhat:rhel_eus:9.2 cpe:/a:redhat:rhel_eus:9.4 cpe:/a:redhat:rhel_tus:8.4 cpe:/a:redhat:rhel_tus:8.6  | 
|
| Vendors & Products | 
        
        Redhat rhel Aus
         Redhat rhel E4s Redhat rhel Eus Redhat rhel Tus  | 
Fri, 07 Mar 2025 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8 | 
Thu, 06 Mar 2025 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat enterprise Linux  | 
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | |
| Vendors & Products | 
        
        Redhat
         Redhat enterprise Linux  | 
Wed, 05 Mar 2025 03:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | firefox: thunderbird: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8 | |
| Weaknesses | CWE-120 | |
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Wed, 05 Mar 2025 00:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | 
| References | 
         | 
Tue, 04 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-787 | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Tue, 04 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mozilla
Published: 2025-03-04T13:31:27.167Z
Updated: 2025-11-03T20:57:25.349Z
Reserved: 2025-03-04T12:29:43.643Z
Link: CVE-2025-1938
Updated: 2025-11-03T20:57:25.349Z
Status : Modified
Published: 2025-03-04T14:15:38.730
Modified: 2025-11-03T21:18:54.993
Link: CVE-2025-1938