CVE-2025-3034: Memory safety bugs fixed in Firefox 137 and Thunderbird 137
Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3034?
CVE-2025-3034 is considered to have a high severity due to potential memory corruption and arbitrary code execution risks.
How do I fix CVE-2025-3034?
To fix CVE-2025-3034, update to the latest versions of Firefox or Thunderbird, specifically version 137 or higher.
What software is affected by CVE-2025-3034?
CVE-2025-3034 affects Firefox versions prior to 137 and Thunderbird versions prior to 137.
What are the potential risks associated with CVE-2025-3034?
The risks include possible exploitation through memory corruption that could lead to arbitrary code execution.
When was CVE-2025-3034 disclosed?
CVE-2025-3034 was disclosed in the security advisories published by Mozilla.