CVE-2025-4082
published 2025-04-29CVE-2025-4082: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.40%
32.8th percentile
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.
*This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 115.23 | 115.23 |
| mozilla | firefox | < 138.0 | 138.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 128.0 < 128.10 | 128.10 |
| mozilla | thunderbird | < 128.10.0 | 128.10.0 |
| mozilla | thunderbird | < 138.0 | 138.0 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-4082: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to
osv·2025-04-29·CVSS 5.9
CVE-2025-4082 [MEDIUM] CVE-2025-4082: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
GHSA
GHSA-xhhw-j3h4-3x9r: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to
ghsa_unreviewed·2025-04-29
CVE-2025-4082 [MEDIUM] CWE-125 GHSA-xhhw-j3h4-3x9r: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.
*This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
Red Hat
firefox: thunderbird: WebGL shader attribute memory corruption in Firefox for macOS
vendor_redhat·2025-04-29·CVSS 5.9
CVE-2025-4082 [MEDIUM] CWE-125 firefox: thunderbird: WebGL shader attribute memory corruption in Firefox for macOS
firefox: thunderbird: WebGL shader attribute memory corruption in Firefox for macOS
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.
*This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. This bug only affects Firefox for macOS. Ot
Debian
CVE-2025-4082: firefox - Modification of specific WebGL shader attributes could trigger an out-of-bounds ...
vendor_debian·2025·CVSS 5.9
CVE-2025-4082 [MEDIUM] CVE-2025-4082: firefox - Modification of specific WebGL shader attributes could trigger an out-of-bounds ...
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-28: CVE-2025-4082
vendor_mozilla·CVSS 5.9
CVE-2025-4082 [MEDIUM] Mozilla Foundation Security Advisory 2025-28: CVE-2025-4082
Mozilla Foundation Security Advisory 2025-28
CVE: CVE-2025-4082
Product: Firefox
Impact: high
Fixed in: Firefox 138
Mozilla
Mozilla Foundation Security Advisory 2025-32: CVE-2025-4082
vendor_mozilla·CVSS 5.9
CVE-2025-4082 [MEDIUM] Mozilla Foundation Security Advisory 2025-32: CVE-2025-4082
Mozilla Foundation Security Advisory 2025-32
CVE: CVE-2025-4082
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 128.10
Mozilla
Mozilla Foundation Security Advisory 2025-30: CVE-2025-4082
vendor_mozilla·CVSS 5.9
CVE-2025-4082 [MEDIUM] Mozilla Foundation Security Advisory 2025-30: CVE-2025-4082
Mozilla Foundation Security Advisory 2025-30
CVE: CVE-2025-4082
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 115.23
Mozilla
Mozilla Foundation Security Advisory 2025-29: CVE-2025-4082
vendor_mozilla·CVSS 5.9
CVE-2025-4082 [MEDIUM] Mozilla Foundation Security Advisory 2025-29: CVE-2025-4082
Mozilla Foundation Security Advisory 2025-29
CVE: CVE-2025-4082
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 128.10
Mozilla
Mozilla Foundation Security Advisory 2025-31: CVE-2025-4082
vendor_mozilla·CVSS 5.9
CVE-2025-4082 [MEDIUM] Mozilla Foundation Security Advisory 2025-31: CVE-2025-4082
Mozilla Foundation Security Advisory 2025-31
CVE: CVE-2025-4082
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 138
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1937097https://www.mozilla.org/security/advisories/mfsa2025-28/https://www.mozilla.org/security/advisories/mfsa2025-29/https://www.mozilla.org/security/advisories/mfsa2025-30/https://www.mozilla.org/security/advisories/mfsa2025-31/https://www.mozilla.org/security/advisories/mfsa2025-32/https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html
2025-04-29
Published