CVE-2025-4919

HIGH

Mozilla Firefox < 115.23.1 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.

Scores

CVSS v3 8.8
EPSS 0.0028
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-125 CWE-787
Status published
Products (9)
mozilla/firefox < 115.23.1
mozilla/firefox < 138.0.4
Mozilla/Firefox 115.23.1 - 115.*
Mozilla/Firefox 128.10.1 - 128.*
Mozilla/Firefox 138.0.4
mozilla/thunderbird < 128.10.2
Mozilla/Thunderbird 128.10.2 - 128.*
mozilla/thunderbird 138.0 - 138.0.2
Mozilla/Thunderbird 138.0.2
Published May 17, 2025
Tracked Since Feb 18, 2026