CVE-2025-9187 Details
Description
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142 and Thunderbird 142.
A vulnerability has been identified in Mozilla Firefox and Thunderbird versions prior to 142, involving memory safety issues that could lead to memory corruption. With sufficient effort, these flaws might have been exploited to execute arbitrary code.
Users can upgrade to Firefox 142 or Thunderbird 142 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1825621%2C1970079%2C1976736%2C1979072 | [email protected] | Broken Link |
| https://www.mozilla.org/security/advisories/mfsa2025-64/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-70/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 142.0 |
CPE
Remediation
| |
| mozilla thunderbird | < 142.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Aug 21, 2025 | Initial Analysis | [email protected] |
| Aug 20, 2025 | CVE Modified | CISA-ADP |
| Aug 19, 2025 | New CVE Received | [email protected] |