INFSA-2025:14743: thunderbird security update

Information about definition

Identificator: INFSA-2025:14743

Type: security

Release date: 2025-09-04 22:13:51 UTC

Information about package

Mozilla Thunderbird is a standalone mail and newsgroup client.

Vulnerabilities description

  • CVE-2025-9179

    A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: An attacker is able to perform memory corruption in the GMP process which process encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process.

  • CVE-2025-9180

    A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Same-origin policy bypass in the Graphics: Canvas2D component.

  • CVE-2025-9181

    A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Uninitialized memory in the JavaScript Engine component.

  • CVE-2025-9182

    A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Denial-of-service due to out-of-memory in the Graphics: WebRender component.

  • CVE-2025-9185

    A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs are present in the following versions: Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141, and Thunderbird 141. Some of these bugs showed evidence of memory corruption, and we presume that with enough effort, some of these could have been exploited to run arbitrary code.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2025-9179
no information 7.5 no information
NIST — CVE-2025-9180
no information 7.5 no information
NIST — CVE-2025-9181
no information 6.1 no information
NIST — CVE-2025-9182
no information 3.4 no information
NIST — CVE-2025-9185
no information 7.5 no information
Critical, important, moderate, low

Updated packages