CVE-2025-9181

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. (en) Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.

03 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html -
  • () https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html -

21 Aug 2025, 18:37

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
First Time Mozilla
Mozilla firefox
Mozilla thunderbird
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1977130 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1977130 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-64/ - () https://www.mozilla.org/security/advisories/mfsa2025-64/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-66/ - () https://www.mozilla.org/security/advisories/mfsa2025-66/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-67/ - () https://www.mozilla.org/security/advisories/mfsa2025-67/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-70/ - () https://www.mozilla.org/security/advisories/mfsa2025-70/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-71/ - () https://www.mozilla.org/security/advisories/mfsa2025-71/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-72/ - () https://www.mozilla.org/security/advisories/mfsa2025-72/ - Vendor Advisory

20 Aug 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-457

20 Aug 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Memoria sin inicializar en el componente JavaScript Engine. Esta vulnerabilidad afecta a Firefox &lt; 142, Firefox ESR &lt; 128.14, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, Thunderbird &lt; 128.14 y Thunderbird &lt; 140.2.

19 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 21:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-9181

Mitre link : CVE-2025-9181

CVE.ORG link : CVE-2025-9181


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-457

Use of Uninitialized Variable