CVE-2025-8033

MEDIUM

Firefox/Thunderbird JavaScript Engine Null Pointer Dereference

Title source: llm
STIX 2.1

Description

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

Scores

CVSS v3 6.5
EPSS 0.0051
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (11)
mozilla/firefox < 115.26.0
mozilla/firefox < 141.0
Mozilla/Firefox 115.26 - 115.*
Mozilla/Firefox 128.13 - 128.*
Mozilla/Firefox 140.1 - 140.*
Mozilla/Firefox 141
mozilla/thunderbird < 128.13.0
mozilla/thunderbird < 141.0
Mozilla/Thunderbird 128.13 - 128.*
Mozilla/Thunderbird 140.1 - 140.*
... and 1 more
Published Jul 22, 2025
Tracked Since Feb 18, 2026