CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.29 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11714?
CVE-2025-11714 is considered to be a high severity vulnerability due to potential memory corruption that could allow arbitrary code execution.
How do I fix CVE-2025-11714?
To fix CVE-2025-11714, update to Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 140.4, Firefox 144, or Thunderbird 144.
Which versions are affected by CVE-2025-11714?
CVE-2025-11714 affects Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143, and Thunderbird 143.
Is CVE-2025-11714 exploitable?
While CVE-2025-11714 displays evidence of memory corruption, exploitation for arbitrary code execution is presumed but not confirmed.
Who is the vendor for CVE-2025-11714?
The vendor for CVE-2025-11714 is Mozilla, which develops Firefox and Thunderbird.