CVE-2025-1943
published 2025-03-04CVE-2025-1943: Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
PriorityP341high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.40%
32.7th percentile
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 136.0-1 (sid) | firefox 136.0-1 (sid) |
| mozilla | firefox | < 136.0 | 136.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 136.0+build3-0ubuntu0.20.04.1 | 136.0+build3-0ubuntu0.20.04.1 |
| mozilla | thunderbird | < 136.0 | 136.0 |
| mozilla | thunderbird | >= 0 < 1:140.7.1+build1-0ubuntu0.22.04.1 | 1:140.7.1+build1-0ubuntu0.22.04.1 |
| msrc | cbl2_kernel_5.15.92.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_kernel_5.10.174.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
firefox: thunderbird: Memory safety bugs fixed in Firefox 136 and Thunderbird 136
vendor_redhat·2025-03-04·CVSS 8.2
CVE-2025-1943 [HIGH] CWE-120 firefox: thunderbird: Memory safety bugs fixed in Firefox 136 and Thunderbird 136
firefox: thunderbird: Memory safety bugs fixed in Firefox 136 and Thunderbird 136
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Thunderbird < 136.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs are present in Firefox 135 and Thunderbird 135. Some of these bugs show evidence of memory corruption and, with enough effort, some of these could be exploited to run arbitrary code.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory
Debian
CVE-2025-1943: firefox - Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bug...
vendor_debian·2025·CVSS 8.2
CVE-2025-1943 [HIGH] CVE-2025-1943: firefox - Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bug...
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Thunderbird < 136.
Scope: local
sid: resolved (fixed in 136.0-1)
Microsoft
A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this fl
vendor_msrc·2022-06-14·CVSS 7.8
CVE-2022-1943 [HIGH] CWE-787 A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this fl
A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional produ
Mozilla
Mozilla Foundation Security Advisory 2025-14: CVE-2025-1943
vendor_mozilla·CVSS 8.2
CVE-2025-1943 [HIGH] Mozilla Foundation Security Advisory 2025-14: CVE-2025-1943
Mozilla Foundation Security Advisory 2025-14
CVE: CVE-2025-1943
Product: Firefox
Impact: high
Fixed in: Firefox 136
Mozilla
Mozilla Foundation Security Advisory 2025-17: CVE-2025-1943
vendor_mozilla·CVSS 8.2
CVE-2025-1943 [HIGH] Mozilla Foundation Security Advisory 2025-17: CVE-2025-1943
Mozilla Foundation Security Advisory 2025-17
CVE: CVE-2025-1943
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 136
GHSA
GHSA-3g8j-6hfm-wj7g: Memory safety bugs present in Firefox 135 and Thunderbird 135
ghsa_unreviewed·2025-03-04
CVE-2025-1943 [HIGH] CWE-122 GHSA-3g8j-6hfm-wj7g: Memory safety bugs present in Firefox 135 and Thunderbird 135
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136.
OSV
CVE-2025-1943: Memory safety bugs present in Firefox 135 and Thunderbird 135
osv·2025-03-04·CVSS 8.2
CVE-2025-1943 [HIGH] CVE-2025-1943: Memory safety bugs present in Firefox 135 and Thunderbird 135
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Thunderbird < 136.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-04
Published