CVE-2025-4087 Details
Description
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbird 128.10.
A vulnerability exists in Mozilla Thunderbird and Firefox due to improper null checks during XPath attribute access. This oversight can cause undefined behavior, allowing out-of-bounds read access that may lead to memory corruption. The issue is present in Firefox versions prior to 138, Firefox ESR versions prior to 128.10, and Thunderbird versions prior to 138 and 128.10.
Users can upgrade to Thunderbird 138 or Firefox 138 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/05/msg00024.html | CVE | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1952465 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-28/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-29/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-31/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-32/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 128.10 < 138.0 |
CPE
Remediation
| |
| mozilla thunderbird | < 128.10.0 < 138.0 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 23, 2025 | CVE Modified | CISA-ADP |
| May 9, 2025 | Initial Analysis | [email protected] |
| May 1, 2025 | CVE Modified | [email protected] |
| Apr 29, 2025 | CVE Modified | CISA-ADP |
| Apr 29, 2025 | New CVE Received | [email protected] |