First published: Tue Apr 29 2025(Updated: )
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <138 | 138 |
Mozilla Thunderbird | <128.10 | 128.10 |
Firefox ESR | <128.10 | 128.10 |
Thunderbird | <138 | 138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity is considered high due to potential memory corruption that could allow execution of arbitrary code.
To fix MFSA-RESERVE-2025-3, update to Firefox version 138 or Thunderbird versions 128.10 or 138.
Affected products include Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird ESR 128.9.
MFSA-RESERVE-2025-3 is associated with memory safety bugs that may lead to memory corruption.
Yes, with sufficient effort, some memory safety bugs in MFSA-RESERVE-2025-3 could potentially be exploited.