CVE-2025-1016
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-1016 refers to a set of memory safety bugs discovered in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. These vulnerabilities involve potential memory corruption, with some evidence suggesting they could be exploited to run arbitrary code. Affected versions include Firefox below 135, Firefox ESR below 115.20, Firefox ESR below 128.7, Thunderbird below 128.7, and Thunderbird below 135. Users are urged to update their browsers and email clients as soon as possible to protect against potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mozilla Thunderbird
- Mozilla Firefox
Affected Vendors
- Mozilla