CVE-2025-5269
🟡 Monitoruj
Błąd bezpieczeństwa pamięci w Firefox ESR i Thunderbird umożliwia potencjalne wykonanie kodu.
CVSS
8.1
EPSS
0.5%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.11 and Thunderbird 128.11.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-05-27 13:15:22 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 18:10:00 UTC |
Referencje
- https://bugzilla.mozilla.org/show_bug.cgi?id=1924108 ([email protected]) [Permissions Required]
- https://www.mozilla.org/security/advisories/mfsa2025-44/ ([email protected]) [Vendor Advisory]
- https://www.mozilla.org/security/advisories/mfsa2025-46/ ([email protected])
- https://lists.debian.org/debian-lts-announce/2025/05/msg00043.html (af854a3a-2127-422b-91ae-364da2661108)
- https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html (af854a3a-2127-422b-91ae-364da2661108)