CVE-2025-49709Out-of-bounds Write in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
0.4%
top 38.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11

Description

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDmozilla/firefox< 139.0.4

🔴Vulnerability Details

3
CVEList
Memory corruption in canvas surfaces2025-06-11
GHSA
GHSA-p5g7-573c-m74m: Certain canvas operations could have lead to memory corruption2025-06-11
OSV
CVE-2025-49709: Certain canvas operations could have lead to memory corruption2025-06-11

📋Vendor Advisories

2
Debian
CVE-2025-49709: firefox - Certain canvas operations could have lead to memory corruption. This vulnerabili...2025
Mozilla
Mozilla Foundation Security Advisory 2025-47: CVE-2025-49709
CVE-2025-49709 — Out-of-bounds Write in Mozilla Firefox | cvebase