thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142

cve CVE-2025-9185 2 sources, 2 claims · Watch

Red Hat writes:
thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 the claim

What it is to other things

affectsmozilla/firefox
NVD
affectsmozilla/thunderbird
NVD
made_bymozilla
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD8.1
receipt
Source
NVD
Its words
8.1
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.27",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "EA30840B-9687-4BD4-B2F6-7557A75D2C5C",
                "versionEndExcluding": "115.27.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "9F095AEE-D972-4427-A063-5CA441E4D1A5",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "02EDFC2B-306B-4DF6-B2DE-8E2B405727B2",
                "versionEndExcluding": "128.14.0",
                "versionStartIncluding": "128.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "4FEE0509-E29D-4C59-A920-60E804499A78",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DCD60324-B41D-4408-B4EF-274DF15E1249",
                "versionEndExcluding": "128.14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "44E5E769-8961-46D3-90E5-DFA27D979F7D",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "28D57F8E-9E36-415C-9A56-8ED3A3B755D4",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2."
      },
      {
        "lang": "es",
        "value": "Errores de seguridad de memoria presentes en Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 y Thunderbird 141. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, algunos de ellos podrían haberse explotado para ejecutar código arbitrario. Esta vulnerabilidad afecta a Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14 y Thunderbird < 140.2."
      }
    ],
    "id": "CVE-2025-9185",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-9185",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-20T03:56:23.417311Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-19T21:15:31.037",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Broken Link"
        ],
        "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1970154%2C1976782%2C1977166"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-64/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-65/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-66/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-67/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-70/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-71/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-72/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat7.5
receipt
Source
Red Hat
Its words
7.5
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-9185",
  "CWE": "CWE-119",
  "advisories": [
    "RHSA-2025:15423",
    "RHSA-2025:15434",
    "RHSA-2025:15424",
    "RHSA-2025:15435",
    "RHSA-2025:14743",
    "RHSA-2025:15535",
    "RHSA-2025:15436",
    "RHSA-2025:15437",
    "RHSA-2025:14844",
    "RHSA-2025:15438",
    "RHSA-2025:14416",
    "RHSA-2025:14417",
    "RHSA-2025:15418",
    "RHSA-2025:15419",
    "RHSA-2025:15430",
    "RHSA-2025:15496",
    "RHSA-2025:15420",
    "RHSA-2025:14442",
    "RHSA-2025:14640",
    "RHSA-2025:15421",
    "RHSA-2025:15422"
  ],
  "affected_packages": [
    "firefox-0:128.14.0-2.el8_10",
    "thunderbird-0:128.14.0-3.el8_10",
    "firefox-0:128.14.0-2.el9_6",
    "firefox-0:128.14.0-2.el8_6",
    "firefox-0:128.14.0-2.el7_9",
    "firefox-0:128.14.0-2.el8_8",
    "thunderbird-0:128.14.0-3.el9_6",
    "thunderbird-0:128.14.0-3.el8_8",
    "firefox-0:128.14.0-2.el9_0",
    "thunderbird-0:128.14.0-3.el9_4",
    "thunderbird-0:128.14.0-3.el8_6",
    "firefox-0:128.14.0-2.el9_2",
    "thunderbird-0:128.14.0-3.el9_2",
    "firefox-0:128.14.0-2.el10_0",
    "thunderbird-0:128.14.0-3.el10_0",
    "firefox-0:128.14.0-2.el8_2",
    "thunderbird-0:128.14.0-3.el8_4",
    "thunderbird-0:128.14.0-3.el9_0",
    "firefox-0:128.14.0-2.el9_4",
    "thunderbird-0:128.14.0-3.el8_2",
    "firefox-0:128.14.0-2.el8_4"
  ],
  "bugzilla": "2389584",
  "bugzilla_description": "thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-08-19T20:33:55Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-9185.json",
  "severity": "important"
}
—
Cwe
cwe
Red HatCWE-119
receipt
Source
Red Hat
Its words
CWE-119
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-9185",
  "CWE": "CWE-119",
  "advisories": [
    "RHSA-2025:15423",
    "RHSA-2025:15434",
    "RHSA-2025:15424",
    "RHSA-2025:15435",
    "RHSA-2025:14743",
    "RHSA-2025:15535",
    "RHSA-2025:15436",
    "RHSA-2025:15437",
    "RHSA-2025:14844",
    "RHSA-2025:15438",
    "RHSA-2025:14416",
    "RHSA-2025:14417",
    "RHSA-2025:15418",
    "RHSA-2025:15419",
    "RHSA-2025:15430",
    "RHSA-2025:15496",
    "RHSA-2025:15420",
    "RHSA-2025:14442",
    "RHSA-2025:14640",
    "RHSA-2025:15421",
    "RHSA-2025:15422"
  ],
  "affected_packages": [
    "firefox-0:128.14.0-2.el8_10",
    "thunderbird-0:128.14.0-3.el8_10",
    "firefox-0:128.14.0-2.el9_6",
    "firefox-0:128.14.0-2.el8_6",
    "firefox-0:128.14.0-2.el7_9",
    "firefox-0:128.14.0-2.el8_8",
    "thunderbird-0:128.14.0-3.el9_6",
    "thunderbird-0:128.14.0-3.el8_8",
    "firefox-0:128.14.0-2.el9_0",
    "thunderbird-0:128.14.0-3.el9_4",
    "thunderbird-0:128.14.0-3.el8_6",
    "firefox-0:128.14.0-2.el9_2",
    "thunderbird-0:128.14.0-3.el9_2",
    "firefox-0:128.14.0-2.el10_0",
    "thunderbird-0:128.14.0-3.el10_0",
    "firefox-0:128.14.0-2.el8_2",
    "thunderbird-0:128.14.0-3.el8_4",
    "thunderbird-0:128.14.0-3.el9_0",
    "firefox-0:128.14.0-2.el9_4",
    "thunderbird-0:128.14.0-3.el8_2",
    "firefox-0:128.14.0-2.el8_4"
  ],
  "bugzilla": "2389584",
  "bugzilla_description": "thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-08-19T20:33:55Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-9185.json",
  "severity": "important"
}
—
Packages
packages
Red Hatfirefox-0:128.14.0-2.el8_10, thunderbird-0:128.14.0-3.el8_10, firefox-0:128.14.0-2.el9_6, firefox-0:128.14.0-2.el8_6, firefox-0:128.14.0-2.el7_9, firefox-0:128.14.0-2.el8_8, thunderbird-0:128.14.0-3.el9_6, thunderbird-0:128.14.0-3.el8_8, firefox-0:128.14.0-2.el9_0, thunderbird-0:128.14.0-3.el9_4, thunderbird-0:128.14.0-3.el8_6, firefox-0:128.14.0-2.el9_2, thunderbird-0:128.14.0-3.el9_2, firefox-0:128.14.0-2.el10_0, thunderbird-0:128.14.0-3.el10_0, firefox-0:128.14.0-2.el8_2, thunderbird-0:128.14.0-3.el8_4, thunderbird-0:128.14.0-3.el9_0, firefox-0:128.14.0-2.el9_4, thunderbird-0:128.14.0-3.el8_2, firefox-0:128.14.0-2.el8_4
receipt
Source
Red Hat
Its words
firefox-0:128.14.0-2.el8_10, thunderbird-0:128.14.0-3.el8_10, firefox-0:128.14.0-2.el9_6, firefox-0:128.14.0-2.el8_6, firefox-0:128.14.0-2.el7_9, firefox-0:128.14.0-2.el8_8, thunderbird-0:128.14.0-3.el9_6, thunderbird-0:128.14.0-3.el8_8, firefox-0:128.14.0-2.el9_0, thunderbird-0:128.14.0-3.el9_4, thunderbird-0:128.14.0-3.el8_6, firefox-0:128.14.0-2.el9_2, thunderbird-0:128.14.0-3.el9_2, firefox-0:128.14.0-2.el10_0, thunderbird-0:128.14.0-3.el10_0, firefox-0:128.14.0-2.el8_2, thunderbird-0:128.14.0-3.el8_4, thunderbird-0:128.14.0-3.el9_0, firefox-0:128.14.0-2.el9_4, thunderbird-0:128.14.0-3.el8_2, firefox-0:128.14.0-2.el8_4
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-9185",
  "CWE": "CWE-119",
  "advisories": [
    "RHSA-2025:15423",
    "RHSA-2025:15434",
    "RHSA-2025:15424",
    "RHSA-2025:15435",
    "RHSA-2025:14743",
    "RHSA-2025:15535",
    "RHSA-2025:15436",
    "RHSA-2025:15437",
    "RHSA-2025:14844",
    "RHSA-2025:15438",
    "RHSA-2025:14416",
    "RHSA-2025:14417",
    "RHSA-2025:15418",
    "RHSA-2025:15419",
    "RHSA-2025:15430",
    "RHSA-2025:15496",
    "RHSA-2025:15420",
    "RHSA-2025:14442",
    "RHSA-2025:14640",
    "RHSA-2025:15421",
    "RHSA-2025:15422"
  ],
  "affected_packages": [
    "firefox-0:128.14.0-2.el8_10",
    "thunderbird-0:128.14.0-3.el8_10",
    "firefox-0:128.14.0-2.el9_6",
    "firefox-0:128.14.0-2.el8_6",
    "firefox-0:128.14.0-2.el7_9",
    "firefox-0:128.14.0-2.el8_8",
    "thunderbird-0:128.14.0-3.el9_6",
    "thunderbird-0:128.14.0-3.el8_8",
    "firefox-0:128.14.0-2.el9_0",
    "thunderbird-0:128.14.0-3.el9_4",
    "thunderbird-0:128.14.0-3.el8_6",
    "firefox-0:128.14.0-2.el9_2",
    "thunderbird-0:128.14.0-3.el9_2",
    "firefox-0:128.14.0-2.el10_0",
    "thunderbird-0:128.14.0-3.el10_0",
    "firefox-0:128.14.0-2.el8_2",
    "thunderbird-0:128.14.0-3.el8_4",
    "thunderbird-0:128.14.0-3.el9_0",
    "firefox-0:128.14.0-2.el9_4",
    "thunderbird-0:128.14.0-3.el8_2",
    "firefox-0:128.14.0-2.el8_4"
  ],
  "bugzilla": "2389584",
  "bugzilla_description": "thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-08-19T20:33:55Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-9185.json",
  "severity": "important"
}
—
Product
product
NVDFirefox
receipt
Source
NVD
Its words
Firefox
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.27",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "EA30840B-9687-4BD4-B2F6-7557A75D2C5C",
                "versionEndExcluding": "115.27.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "9F095AEE-D972-4427-A063-5CA441E4D1A5",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "02EDFC2B-306B-4DF6-B2DE-8E2B405727B2",
                "versionEndExcluding": "128.14.0",
                "versionStartIncluding": "128.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "4FEE0509-E29D-4C59-A920-60E804499A78",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DCD60324-B41D-4408-B4EF-274DF15E1249",
                "versionEndExcluding": "128.14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "44E5E769-8961-46D3-90E5-DFA27D979F7D",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "28D57F8E-9E36-415C-9A56-8ED3A3B755D4",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2."
      },
      {
        "lang": "es",
        "value": "Errores de seguridad de memoria presentes en Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 y Thunderbird 141. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, algunos de ellos podrían haberse explotado para ejecutar código arbitrario. Esta vulnerabilidad afecta a Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14 y Thunderbird < 140.2."
      }
    ],
    "id": "CVE-2025-9185",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-9185",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-20T03:56:23.417311Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-19T21:15:31.037",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Broken Link"
        ],
        "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1970154%2C1976782%2C1977166"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-64/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-65/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-66/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-67/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-70/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-71/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-72/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-9185",
  "CWE": "CWE-119",
  "advisories": [
    "RHSA-2025:15423",
    "RHSA-2025:15434",
    "RHSA-2025:15424",
    "RHSA-2025:15435",
    "RHSA-2025:14743",
    "RHSA-2025:15535",
    "RHSA-2025:15436",
    "RHSA-2025:15437",
    "RHSA-2025:14844",
    "RHSA-2025:15438",
    "RHSA-2025:14416",
    "RHSA-2025:14417",
    "RHSA-2025:15418",
    "RHSA-2025:15419",
    "RHSA-2025:15430",
    "RHSA-2025:15496",
    "RHSA-2025:15420",
    "RHSA-2025:14442",
    "RHSA-2025:14640",
    "RHSA-2025:15421",
    "RHSA-2025:15422"
  ],
  "affected_packages": [
    "firefox-0:128.14.0-2.el8_10",
    "thunderbird-0:128.14.0-3.el8_10",
    "firefox-0:128.14.0-2.el9_6",
    "firefox-0:128.14.0-2.el8_6",
    "firefox-0:128.14.0-2.el7_9",
    "firefox-0:128.14.0-2.el8_8",
    "thunderbird-0:128.14.0-3.el9_6",
    "thunderbird-0:128.14.0-3.el8_8",
    "firefox-0:128.14.0-2.el9_0",
    "thunderbird-0:128.14.0-3.el9_4",
    "thunderbird-0:128.14.0-3.el8_6",
    "firefox-0:128.14.0-2.el9_2",
    "thunderbird-0:128.14.0-3.el9_2",
    "firefox-0:128.14.0-2.el10_0",
    "thunderbird-0:128.14.0-3.el10_0",
    "firefox-0:128.14.0-2.el8_2",
    "thunderbird-0:128.14.0-3.el8_4",
    "thunderbird-0:128.14.0-3.el9_0",
    "firefox-0:128.14.0-2.el9_4",
    "thunderbird-0:128.14.0-3.el8_2",
    "firefox-0:128.14.0-2.el8_4"
  ],
  "bugzilla": "2389584",
  "bugzilla_description": "thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-08-19T20:33:55Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-9185.json",
  "severity": "important"
}
high
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.27",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "EA30840B-9687-4BD4-B2F6-7557A75D2C5C",
                "versionEndExcluding": "115.27.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "9F095AEE-D972-4427-A063-5CA441E4D1A5",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "02EDFC2B-306B-4DF6-B2DE-8E2B405727B2",
                "versionEndExcluding": "128.14.0",
                "versionStartIncluding": "128.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "4FEE0509-E29D-4C59-A920-60E804499A78",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DCD60324-B41D-4408-B4EF-274DF15E1249",
                "versionEndExcluding": "128.14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "44E5E769-8961-46D3-90E5-DFA27D979F7D",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "28D57F8E-9E36-415C-9A56-8ED3A3B755D4",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2."
      },
      {
        "lang": "es",
        "value": "Errores de seguridad de memoria presentes en Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 y Thunderbird 141. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, algunos de ellos podrían haberse explotado para ejecutar código arbitrario. Esta vulnerabilidad afecta a Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14 y Thunderbird < 140.2."
      }
    ],
    "id": "CVE-2025-9185",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-9185",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-20T03:56:23.417311Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-19T21:15:31.037",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Broken Link"
        ],
        "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1970154%2C1976782%2C1977166"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-64/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-65/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-66/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-67/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-70/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-71/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-72/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDMozilla
receipt
Source
NVD
Its words
Mozilla
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.27",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.14",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "140.*",
                "status": "unaffected",
                "version": "140.2",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "142",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "EA30840B-9687-4BD4-B2F6-7557A75D2C5C",
                "versionEndExcluding": "115.27.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "9F095AEE-D972-4427-A063-5CA441E4D1A5",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "02EDFC2B-306B-4DF6-B2DE-8E2B405727B2",
                "versionEndExcluding": "128.14.0",
                "versionStartIncluding": "128.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "4FEE0509-E29D-4C59-A920-60E804499A78",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DCD60324-B41D-4408-B4EF-274DF15E1249",
                "versionEndExcluding": "128.14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "44E5E769-8961-46D3-90E5-DFA27D979F7D",
                "versionEndExcluding": "142.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "28D57F8E-9E36-415C-9A56-8ED3A3B755D4",
                "versionEndExcluding": "140.2.0",
                "versionStartIncluding": "140.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2."
      },
      {
        "lang": "es",
        "value": "Errores de seguridad de memoria presentes en Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 y Thunderbird 141. Algunos de estos errores mostraron evidencia de corrupción de memoria y presumimos que, con suficiente esfuerzo, algunos de ellos podrían haberse explotado para ejecutar código arbitrario. Esta vulnerabilidad afecta a Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14 y Thunderbird < 140.2."
      }
    ],
    "id": "CVE-2025-9185",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-9185",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-20T03:56:23.417311Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-19T21:15:31.037",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Broken Link"
        ],
        "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1970154%2C1976782%2C1977166"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-64/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-65/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-66/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-67/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-70/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-71/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-72/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
zetlyn/cve-redhat · 2025-08-19
cvss 7.5 cwe CWE-119 packages firefox-0:128.14.0-2.el8_10, thunderbird-0:128.14.0-3.el8_10, firefox-0:128.14.0-2.el9_6, firefox-0:128.14.0-2.el8_6, firefox-0:128.14.0-2.el7_9, firefox-0:128.14.0-2.el8_8, thunderbird-0:128.14.0-3.el9_6, thunderbird-0:128.14.0-3.el8_8, firefox-0:128.14.0-2.el9_0, thunderbird-0:128.14.0-3.el9_4, thunderbird-0:128.14.0-3.el8_6, firefox-0:128.14.0-2.el9_2, thunderbird-0:128.14.0-3.el9_2, firefox-0:128.14.0-2.el10_0, thunderbird-0:128.14.0-3.el10_0, firefox-0:128.14.0-2.el8_2, thunderbird-0:128.14.0-3.el8_4, thunderbird-0:128.14.0-3.el9_0, firefox-0:128.14.0-2.el9_4, thunderbird-0:128.14.0-3.el8_2, firefox-0:128.14.0-2.el8_4 severity important source
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
zetlyn/cve-nvd · 2025-08-19
cvss 8.1 product Firefox status Modified vendor Mozilla source