First published: Tue Apr 01 2025(Updated: )
Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <128.9 | 128.9 |
Thunderbird | <137 | 137 |
Mozilla Thunderbird | <128.9 | 128.9 |
Firefox | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2025-3030 is considered a high severity vulnerability due to its potential for memory corruption leading to arbitrary code execution.
To fix CVE-2025-3030, update Firefox to version 137, Firefox ESR to version 128.9, or Thunderbird to version 137.
CVE-2025-3030 affects Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird ESR 128.8.
Yes, CVE-2025-3030 has the potential to be exploited remotely if an attacker can invoke the memory safety bugs.
Memory safety bugs are vulnerabilities that occur when a program improperly manages memory, leading to potential exploitation such as arbitrary code execution.