V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-8044
ANC
Critical

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that …

CVSS
9.8
Critical
EPSS
0.00
p33
Published
2025-01-01
Updated
2025-01-01
Description

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141 and Thunderbird < 141.

Tags · CWE
RCEPre-auth
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Firefox < 141.0Thunderbird < 141.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.004 · p33
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
Tracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
mozjs102Tracked
mozjs102Tracked
mozjs115Tracked
mozjs115Tracked
mozjs78Tracked
mozjs91Tracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
firefox*Tracked
Showing first 20 of 21
Source databases
ANC
AST
DEB
CVE
UBU
Related vulnerabilities