CVE-2025-5262

A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

19 Sep 2025, 17:18

Type Values Removed Values Added
CWE CWE-415
First Time Mozilla
Mozilla thunderbird
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1962421 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1962421 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-45/ - () https://www.mozilla.org/security/advisories/mfsa2025-45/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-46/ - () https://www.mozilla.org/security/advisories/mfsa2025-46/ - Vendor Advisory

20 Aug 2025, 14:40

Type Values Removed Values Added
Summary
  • (es) Podría haberse producido una doble liberación en `vpx_codec_enc_init_multi` tras un error de asignación al inicializar el codificador para WebRTC. Esto podría haber causado corrupción de memoria y un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Thunderbird (versión anterior a la 139) y Thunderbird (versión anterior a la 128.11).

19 Aug 2025, 21:15

Type Values Removed Values Added
Summary (en) Rejected reason: This CVE was accidentally assigned by Mozilla but should be assigned by another CNA. When the correct CVE is available, Mozilla's advisories will be updated to reflect that identifier. (en) A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
References
  • () https://bugzilla.mozilla.org/show_bug.cgi?id=1962421 -
  • () https://www.mozilla.org/security/advisories/mfsa2025-45/ -
  • () https://www.mozilla.org/security/advisories/mfsa2025-46/ -

27 May 2025, 18:15

Type Values Removed Values Added
CWE CWE-415
Summary (en) A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. (en) Rejected reason: This CVE was accidentally assigned by Mozilla but should be assigned by another CNA. When the correct CVE is available, Mozilla's advisories will be updated to reflect that identifier.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
References
  • {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1962421', 'source': 'security@mozilla.org'}
  • {'url': 'https://www.mozilla.org/security/advisories/mfsa2025-42/', 'source': 'security@mozilla.org'}
  • {'url': 'https://www.mozilla.org/security/advisories/mfsa2025-43/', 'source': 'security@mozilla.org'}
  • {'url': 'https://www.mozilla.org/security/advisories/mfsa2025-44/', 'source': 'security@mozilla.org'}

27 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-415
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 13:15

Updated : 2025-09-19 17:18


NVD link : CVE-2025-5262

Mitre link : CVE-2025-5262

CVE.ORG link : CVE-2025-5262


JSON object : View

Products Affected

mozilla

  • thunderbird
CWE
CWE-415

Double Free