CVE-2025-3030: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9
Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3030?
CVE-2025-3030 is considered a high severity vulnerability due to its potential for memory corruption leading to arbitrary code execution.
How do I fix CVE-2025-3030?
To fix CVE-2025-3030, update Firefox to version 137, Firefox ESR to version 128.9, or Thunderbird to version 137.
What products are affected by CVE-2025-3030?
CVE-2025-3030 affects Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird ESR 128.8.
Can CVE-2025-3030 be exploited remotely?
Yes, CVE-2025-3030 has the potential to be exploited remotely if an attacker can invoke the memory safety bugs.
What are memory safety bugs?
Memory safety bugs are vulnerabilities that occur when a program improperly manages memory, leading to potential exploitation such as arbitrary code execution.