CVE-2025-9181
6.5MEDIUMUninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird <
Published: 8/19/2025Updated: 11/3/2025
Description
Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
AI AnalysisPowered by AI
Affected Products
mozillafirefox
mozillafirefox
mozillafirefox
mozillathunderbird
mozillathunderbird
mozillathunderbird
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1977130Issue TrackingPermissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-64/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-66/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-67/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-70/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-71/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-72/Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html
- https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html