CVE Vulnerabilities

CVE-2025-9185

Published: Aug 19, 2025 | Modified: Nov 03, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*115.27.0 (excluding)
FirefoxMozilla*142.0 (excluding)
FirefoxMozilla128.0 (including)128.14.0 (excluding)
FirefoxMozilla140.0 (including)140.2.0 (excluding)
ThunderbirdMozilla*128.14.0 (excluding)
ThunderbirdMozilla*142.0 (excluding)
ThunderbirdMozilla140.0 (including)140.2.0 (excluding)
Red Hat Enterprise Linux 10RedHatfirefox-0:128.14.0-2.el10_0*
Red Hat Enterprise Linux 10RedHatthunderbird-0:128.14.0-3.el10_0*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatfirefox-0:128.14.0-2.el7_9*
Red Hat Enterprise Linux 8RedHatfirefox-0:128.14.0-2.el8_10*
Red Hat Enterprise Linux 8RedHatthunderbird-0:128.14.0-3.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatfirefox-0:128.14.0-2.el8_2*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatthunderbird-0:128.14.0-3.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatfirefox-0:128.14.0-2.el8_4*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatthunderbird-0:128.14.0-3.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatfirefox-0:128.14.0-2.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatthunderbird-0:128.14.0-3.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatfirefox-0:128.14.0-2.el8_6*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatthunderbird-0:128.14.0-3.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatfirefox-0:128.14.0-2.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatthunderbird-0:128.14.0-3.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatfirefox-0:128.14.0-2.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatthunderbird-0:128.14.0-3.el8_6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatfirefox-0:128.14.0-2.el8_8*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatthunderbird-0:128.14.0-3.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatfirefox-0:128.14.0-2.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatthunderbird-0:128.14.0-3.el8_8*
Red Hat Enterprise Linux 9RedHatfirefox-0:128.14.0-2.el9_6*
Red Hat Enterprise Linux 9RedHatthunderbird-0:128.14.0-3.el9_6*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatfirefox-0:128.14.0-2.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatthunderbird-0:128.14.0-3.el9_0*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatfirefox-0:128.14.0-2.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatthunderbird-0:128.14.0-3.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatfirefox-0:128.14.0-2.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatthunderbird-0:128.14.0-3.el9_4*
Mozjs102Ubuntuesm-apps/noble*
Mozjs102Ubuntujammy*
Mozjs102Ubuntunoble*
Mozjs115Ubuntunoble*
Mozjs115Ubuntuplucky*
Mozjs52Ubuntuesm-apps/focal*
Mozjs52Ubuntuesm-infra/bionic*
Mozjs68Ubuntuesm-infra/focal*
Mozjs78Ubuntuesm-apps/jammy*
Mozjs78Ubuntujammy*
Mozjs91Ubuntujammy*
ThunderbirdUbuntujammy*

References