firefox: Compartment mismatch when parsing JavaScript JSON module

zetlyn/cve-redhat vulnerability cve CVE-2025-0240 known 2025-01-07

https://access.redhat.com/security/cve/CVE-2025-0240

Properties

cvss6.5
receipt
Source
Red Hat
Its words
6.5
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-0240",
  "CWE": "CWE-416",
  "advisories": [
    "RHSA-2025:0138",
    "RHSA-2025:0137",
    "RHSA-2025:0134",
    "RHSA-2025:0167",
    "RHSA-2025:0144",
    "RHSA-2025:0133",
    "RHSA-2025:0287",
    "RHSA-2025:0166",
    "RHSA-2025:0136",
    "RHSA-2025:0147",
    "RHSA-2025:0135",
    "RHSA-2025:0284",
    "RHSA-2025:0162",
    "RHSA-2025:0132",
    "RHSA-2025:0286",
    "RHSA-2025:0275",
    "RHSA-2025:0165",
    "RHSA-2025:0281",
    "RHSA-2025:0080"
  ],
  "affected_packages": [
    "firefox-0:128.6.0-1.el9_0",
    "firefox-0:128.6.0-1.el8_4",
    "firefox-0:128.6.0-1.el9_4",
    "firefox-0:128.6.0-1.el8_2",
    "firefox-0:128.6.0-1.el8_10",
    "firefox-0:128.6.0-1.el9_2",
    "firefox-0:128.6.0-1.el7_9",
    "thunderbird-0:128.6.0-3.el8_10",
    "thunderbird-0:128.6.0-3.el8_4",
    "firefox-0:128.6.0-1.el8_8",
    "thunderbird-0:128.6.0-3.el9_4",
    "firefox-0:128.6.0-1.el8_6",
    "thunderbird-0:128.6.0-3.el8_6",
    "firefox-0:128.6.0-1.el9_5",
    "thunderbird-0:128.6.0-3.el9_5",
    "thunderbird-0:128.6.0-3.el9_0",
    "thunderbird-0:128.6.0-3.el8_2",
    "thunderbird-0:128.6.0-3.el9_2",
    "thunderbird-0:128.6.0-3.el8_8"
  ],
  "bugzilla": "2336188",
  "bugzilla_description": "firefox: Compartment mismatch when parsing JavaScript JSON module",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-01-07T16:07:06Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-0240.json",
  "severity": "moderate"
}
cweCWE-416
receipt
Source
Red Hat
Its words
CWE-416
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-0240",
  "CWE": "CWE-416",
  "advisories": [
    "RHSA-2025:0138",
    "RHSA-2025:0137",
    "RHSA-2025:0134",
    "RHSA-2025:0167",
    "RHSA-2025:0144",
    "RHSA-2025:0133",
    "RHSA-2025:0287",
    "RHSA-2025:0166",
    "RHSA-2025:0136",
    "RHSA-2025:0147",
    "RHSA-2025:0135",
    "RHSA-2025:0284",
    "RHSA-2025:0162",
    "RHSA-2025:0132",
    "RHSA-2025:0286",
    "RHSA-2025:0275",
    "RHSA-2025:0165",
    "RHSA-2025:0281",
    "RHSA-2025:0080"
  ],
  "affected_packages": [
    "firefox-0:128.6.0-1.el9_0",
    "firefox-0:128.6.0-1.el8_4",
    "firefox-0:128.6.0-1.el9_4",
    "firefox-0:128.6.0-1.el8_2",
    "firefox-0:128.6.0-1.el8_10",
    "firefox-0:128.6.0-1.el9_2",
    "firefox-0:128.6.0-1.el7_9",
    "thunderbird-0:128.6.0-3.el8_10",
    "thunderbird-0:128.6.0-3.el8_4",
    "firefox-0:128.6.0-1.el8_8",
    "thunderbird-0:128.6.0-3.el9_4",
    "firefox-0:128.6.0-1.el8_6",
    "thunderbird-0:128.6.0-3.el8_6",
    "firefox-0:128.6.0-1.el9_5",
    "thunderbird-0:128.6.0-3.el9_5",
    "thunderbird-0:128.6.0-3.el9_0",
    "thunderbird-0:128.6.0-3.el8_2",
    "thunderbird-0:128.6.0-3.el9_2",
    "thunderbird-0:128.6.0-3.el8_8"
  ],
  "bugzilla": "2336188",
  "bugzilla_description": "firefox: Compartment mismatch when parsing JavaScript JSON module",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-01-07T16:07:06Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-0240.json",
  "severity": "moderate"
}
packagesfirefox-0:128.6.0-1.el9_0, firefox-0:128.6.0-1.el8_4, firefox-0:128.6.0-1.el9_4, firefox-0:128.6.0-1.el8_2, firefox-0:128.6.0-1.el8_10, firefox-0:128.6.0-1.el9_2, firefox-0:128.6.0-1.el7_9, thunderbird-0:128.6.0-3.el8_10, thunderbird-0:128.6.0-3.el8_4, firefox-0:128.6.0-1.el8_8, thunderbird-0:128.6.0-3.el9_4, firefox-0:128.6.0-1.el8_6, thunderbird-0:128.6.0-3.el8_6, firefox-0:128.6.0-1.el9_5, thunderbird-0:128.6.0-3.el9_5, thunderbird-0:128.6.0-3.el9_0, thunderbird-0:128.6.0-3.el8_2, thunderbird-0:128.6.0-3.el9_2, thunderbird-0:128.6.0-3.el8_8
receipt
Source
Red Hat
Its words
firefox-0:128.6.0-1.el9_0, firefox-0:128.6.0-1.el8_4, firefox-0:128.6.0-1.el9_4, firefox-0:128.6.0-1.el8_2, firefox-0:128.6.0-1.el8_10, firefox-0:128.6.0-1.el9_2, firefox-0:128.6.0-1.el7_9, thunderbird-0:128.6.0-3.el8_10, thunderbird-0:128.6.0-3.el8_4, firefox-0:128.6.0-1.el8_8, thunderbird-0:128.6.0-3.el9_4, firefox-0:128.6.0-1.el8_6, thunderbird-0:128.6.0-3.el8_6, firefox-0:128.6.0-1.el9_5, thunderbird-0:128.6.0-3.el9_5, thunderbird-0:128.6.0-3.el9_0, thunderbird-0:128.6.0-3.el8_2, thunderbird-0:128.6.0-3.el9_2, thunderbird-0:128.6.0-3.el8_8
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-0240",
  "CWE": "CWE-416",
  "advisories": [
    "RHSA-2025:0138",
    "RHSA-2025:0137",
    "RHSA-2025:0134",
    "RHSA-2025:0167",
    "RHSA-2025:0144",
    "RHSA-2025:0133",
    "RHSA-2025:0287",
    "RHSA-2025:0166",
    "RHSA-2025:0136",
    "RHSA-2025:0147",
    "RHSA-2025:0135",
    "RHSA-2025:0284",
    "RHSA-2025:0162",
    "RHSA-2025:0132",
    "RHSA-2025:0286",
    "RHSA-2025:0275",
    "RHSA-2025:0165",
    "RHSA-2025:0281",
    "RHSA-2025:0080"
  ],
  "affected_packages": [
    "firefox-0:128.6.0-1.el9_0",
    "firefox-0:128.6.0-1.el8_4",
    "firefox-0:128.6.0-1.el9_4",
    "firefox-0:128.6.0-1.el8_2",
    "firefox-0:128.6.0-1.el8_10",
    "firefox-0:128.6.0-1.el9_2",
    "firefox-0:128.6.0-1.el7_9",
    "thunderbird-0:128.6.0-3.el8_10",
    "thunderbird-0:128.6.0-3.el8_4",
    "firefox-0:128.6.0-1.el8_8",
    "thunderbird-0:128.6.0-3.el9_4",
    "firefox-0:128.6.0-1.el8_6",
    "thunderbird-0:128.6.0-3.el8_6",
    "firefox-0:128.6.0-1.el9_5",
    "thunderbird-0:128.6.0-3.el9_5",
    "thunderbird-0:128.6.0-3.el9_0",
    "thunderbird-0:128.6.0-3.el8_2",
    "thunderbird-0:128.6.0-3.el9_2",
    "thunderbird-0:128.6.0-3.el8_8"
  ],
  "bugzilla": "2336188",
  "bugzilla_description": "firefox: Compartment mismatch when parsing JavaScript JSON module",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-01-07T16:07:06Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-0240.json",
  "severity": "moderate"
}
severitymoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-0240",
  "CWE": "CWE-416",
  "advisories": [
    "RHSA-2025:0138",
    "RHSA-2025:0137",
    "RHSA-2025:0134",
    "RHSA-2025:0167",
    "RHSA-2025:0144",
    "RHSA-2025:0133",
    "RHSA-2025:0287",
    "RHSA-2025:0166",
    "RHSA-2025:0136",
    "RHSA-2025:0147",
    "RHSA-2025:0135",
    "RHSA-2025:0284",
    "RHSA-2025:0162",
    "RHSA-2025:0132",
    "RHSA-2025:0286",
    "RHSA-2025:0275",
    "RHSA-2025:0165",
    "RHSA-2025:0281",
    "RHSA-2025:0080"
  ],
  "affected_packages": [
    "firefox-0:128.6.0-1.el9_0",
    "firefox-0:128.6.0-1.el8_4",
    "firefox-0:128.6.0-1.el9_4",
    "firefox-0:128.6.0-1.el8_2",
    "firefox-0:128.6.0-1.el8_10",
    "firefox-0:128.6.0-1.el9_2",
    "firefox-0:128.6.0-1.el7_9",
    "thunderbird-0:128.6.0-3.el8_10",
    "thunderbird-0:128.6.0-3.el8_4",
    "firefox-0:128.6.0-1.el8_8",
    "thunderbird-0:128.6.0-3.el9_4",
    "firefox-0:128.6.0-1.el8_6",
    "thunderbird-0:128.6.0-3.el8_6",
    "firefox-0:128.6.0-1.el9_5",
    "thunderbird-0:128.6.0-3.el9_5",
    "thunderbird-0:128.6.0-3.el9_0",
    "thunderbird-0:128.6.0-3.el8_2",
    "thunderbird-0:128.6.0-3.el9_2",
    "thunderbird-0:128.6.0-3.el8_8"
  ],
  "bugzilla": "2336188",
  "bugzilla_description": "firefox: Compartment mismatch when parsing JavaScript JSON module",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-01-07T16:07:06Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-0240.json",
  "severity": "moderate"
}

Text

firefox: Compartment mismatch when parsing JavaScript JSON module