CVE-2025-0242: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6
Last updated 9 January 2025
Other sources
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0242?
CVE-2025-0242 is categorized as a memory safety vulnerability with potential for exploitation.
How do I fix CVE-2025-0242?
To fix CVE-2025-0242, update your Firefox, Thunderbird, or Firefox ESR to version 115.19, 134, or higher.
Which versions are affected by CVE-2025-0242?
CVE-2025-0242 affects Firefox 133, Thunderbird 133, Firefox ESR versions 115.18 and 128.5, among others.
Is CVE-2025-0242 exploitable?
Yes, CVE-2025-0242 may be exploitable under certain conditions due to memory corruption issues.
What products are impacted by CVE-2025-0242?
CVE-2025-0242 impacts Mozilla Firefox, Mozilla Thunderbird, and their respective ESR versions.