INFCSA-2025:18155: firefox security update
Information about definition
Identificator: INFCSA-2025:18155
Type: security
Release date: 2025-11-11 15:21:00 UTC
Information about package
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Vulnerabilities description
- CVE-2025-11708
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in MediaTrackGraphImpl::GetInstance(). By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
- CVE-2025-11709
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds read/write in a privileged process triggered by WebGL textures. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
- CVE-2025-11710
Mozilla Firefox could allow a remote attacker to obtain sensitive information, caused by the leaking of cross-process information due to malicious IPC messages. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to obtain sensitive information.
- CVE-2025-11711
Mozilla Firefox could allow a remote attacker to bypass security restrictions. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to modify some non-writable Object properties.
- CVE-2025-11712
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header.
- CVE-2025-11714
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
- CVE-2025-11715
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
Severity level
| CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
|---|---|---|---|
|
NIST — CVE-2025-11708
|
no information | 7.5 | no information |
|
NIST — CVE-2025-11709
|
no information | 7.5 | no information |
|
NIST — CVE-2025-11710
|
no information | 7.5 | no information |
|
NIST — CVE-2025-11711
|
no information | 7.5 | no information |
|
NIST — CVE-2025-11712
|
no information | 6.1 | no information |
|
NIST — CVE-2025-11714
|
no information | 7.5 | no information |
|
NIST — CVE-2025-11715
|
no information | 7.5 | no information |
Updated packages