First published: Tue Feb 04 2025(Updated: )
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <135 | 135 |
Mozilla Firefox | <135 | 135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-1020 is considered a high-severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2025-1020, upgrade to Firefox or Thunderbird version 135 or later.
Firefox versions up to and including 134 are affected by CVE-2025-1020.
Thunderbird versions up to and including 134 are affected by CVE-2025-1020.
CVE-2025-1020 includes memory safety bugs that could potentially lead to memory corruption.