CVE-2025-0238

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 7, 2025
Updated: Jan 13, 2025
CWE ID 416

Summary

CVE-2025-0238 is a use-after-free vulnerability that can be exploited when Firefox versions prior to 134 and Firefox ESR versions prior to 128.6, as well as Thunderbird versions prior to 134 and Thunderbird versions prior to 115.19, fail to allocate memory properly. An attacker who can cause a controlled failed memory allocation may succeed in accessing previously freed memory, potentially resulting in a crash that could be exploited for malicious purposes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share