CVE-2025-0238

Executive Summary

CVE-2025-0238: A controlled failed memory allocation in Firefox and Thunderbird could trigger a use‑after‑free, potentially causing a crash or exploitation. The issue is fixed in Firefox 134/ESR 128.6/115.19 and Thunderbird 134/128.6. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 5.3 (MEDIUM) - Published: 2025-01-07T16:15:38.470 - Last Modified: 2026-10-05T15:10:00.590

Original Description: Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Firefox ESR 115.19, Thunderbird 134, and Thunderbird 128.6.

"You are the only person on earth who can use your ability."

— Zig Ziglar
Source: NVD