CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11
Published May 27, 2025
·Updated
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code.
Affected Software
6 affected componentsFixes available
Mozilla Firefox ESR<128.11
Mozilla Thunderbird
Mozilla Thunderbird<128.11
128.11
Mozilla Firefox ESR<128.11
128.11
Mozilla Firefox<128.11.0
Mozilla Thunderbird<128.11.0
Event History
May 27, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-5269?
CVE-2025-5269 is classified as a memory safety bug that could potentially lead to arbitrary code execution.
2
How do I fix CVE-2025-5269?
To fix CVE-2025-5269, update to Firefox ESR version 128.11 or later.
3
Which software is affected by CVE-2025-5269?
CVE-2025-5269 affects Firefox ESR version 128.10 and Thunderbird version 128.10.
4
Can CVE-2025-5269 be exploited?
There is evidence that CVE-2025-5269 could be exploited to run arbitrary code with enough effort.
5
What are the potential consequences of CVE-2025-5269?
The consequences of CVE-2025-5269 include possible memory corruption and exploitation leading to unauthorized code execution.