CVE-2025-4919: Out-of-bounds access when optimizing linear sums
Published May 17, 2025
·Updated
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes.
Affected Software
11 affected componentsFixes available
Mozilla Firefox ESR<115.23.1
Mozilla Firefox ESR<115.23.1
115.23.1
Mozilla Firefox<138.0.4
138.0.4
Mozilla Firefox ESR<128.10.1
128.10.1
Mozilla Thunderbird<138.0.2
138.0.2
Mozilla Thunderbird<128.10.2
128.10.2
Mozilla Firefox<115.23.1
Mozilla Firefox<138.0.4
Mozilla Firefox>=116.0<128.10.1
Mozilla Thunderbird<128.10.2
Mozilla Thunderbird>=138.0<138.0.2
Event History
May 17, 2025
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
Description
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
May 19, 2025
News Published
via BleepingComputer·02:03 PM
News Published
via BleepingComputer·02:10 PM
News Published
via BleepingComputer·02:12 PM
May 23, 2025
Known Exploited
02:05 PM
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-4919?
CVE-2025-4919 has been categorized as a critical severity vulnerability due to its potential to allow unauthorized access to sensitive data.
2
How do I fix CVE-2025-4919?
To fix CVE-2025-4919, update your Mozilla Firefox ESR to version 115.23.1 or later.
3
What is the impact of CVE-2025-4919?
CVE-2025-4919 can allow attackers to perform out-of-bounds read or write operations on JavaScript objects, leading to potential data corruption or exposure.
4
Which versions are affected by CVE-2025-4919?
CVE-2025-4919 affects Firefox ESR versions below 115.23.1.
5
Who is the vendor associated with CVE-2025-4919?
The vendor associated with CVE-2025-4919 is Mozilla.