Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-esrUpgrade thunderbird-esr | Jul 25, 2025 | Jul 24, 2025 |
| Mfsa2025 56 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 141.0 | Jul 23, 2025 | Jul 22, 2025 |
| Mfsa2025 59 | — | Upgrade to Mozilla Firefox ESR version 140.1Upgrade to the latest version of Mozilla Firefox | Jul 23, 2025 | Jul 22, 2025 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 140.1 | Jul 23, 2025 | Jul 22, 2025 |
| Suse | — | Upgrade pipewire-spa-plugins-0_2Upgrade pipewireUpgrade gstreamer-plugin-pipewireUpgrade xdg-desktop-portalUpgrade MozillaFirefox-develUpgrade pipewire-toolsUpgrade xdg-desktop-portal-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-otherUpgrade xdg-desktop-portal-langUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbirdUpgrade pipewire-spa-toolsUpgrade pipewire-langUpgrade pipewire-modulesUpgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade libpipewire-0_3-0Upgrade MozillaFirefoxUpgrade mozillafirefox-branding-sleUpgrade pipewire-modules-0_3 | Dec 5, 2025 | Jul 25, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 24, 2025 | Jul 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub