CVE-2025-1937: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
Last updated 6 March 2025
Other sources
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1937?
CVE-2025-1937 is considered a high severity vulnerability due to potential memory corruption that could allow arbitrary code execution.
How do I fix CVE-2025-1937?
To fix CVE-2025-1937, update Mozilla Firefox to version 136, Mozilla Firefox ESR to version 115.21 or 128.8, or update Mozilla Thunderbird to version 136.
What are the affected products for CVE-2025-1937?
The affected products for CVE-2025-1937 include Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7.
Is CVE-2025-1937 easy to exploit?
While CVE-2025-1937 shows evidence of memory corruption, exploiting it to run arbitrary code would require significant effort.
What types of vulnerabilities does CVE-2025-1937 involve?
CVE-2025-1937 involves memory safety bugs that can lead to memory corruption in the software.