Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142 and Thunderbird 142.
Conclusion & alert: CVE-2025-9187 is rated Moderate Risk (45.3/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-08-25 | 0.02% | 0.06% | +0.04% |
| 2 | 2025-08-20 | — | 0.02% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-9187: 2 source package rows (firefox, thunderbird); 228 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 228. | https://security.alpinelinux.org/vuln/CVE-2025-9187 |
debian
|
not yet assigned | CVE-2025-9187 not yet assigned priority: Debian including 1 source packages (firefox), 1 status rows across 1 suites (sid): resolved 1. | https://security-tracker.debian.org/tracker/CVE-2025-9187 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-9187 |
suse
|
high | CVE-2025-9187 severity important: SUSE including 89 source package names (2.0.4-3.5.412:libfreebl3-3.112.2-150400.3.60.1, 2.0.4-3.5.412:libsoftokn3-3.112.2-150400.3.60.1, …), 1038 product×package rows across 224 product lines (Container bci/kiwi, Container suse/manager/5.0/x86_64/server, … (224 product lines)): Fixed 1038. | https://www.suse.com/security/cve/CVE-2025-9187/ |
ubuntu
|
medium | CVE-2025-9187 medium priority: Ubuntu including 9 source packages (firefox, mozjs102, …), 49 status rows across 7 suites (bionic, focal, jammy, noble, plucky, questing, upstream): DNE 22, needs-triage 10, ignored 9, not-affected 8. | https://ubuntu.com/security/CVE-2025-9187 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mozilla | firefox | < 142.0 | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* |
| mozilla | thunderbird | < 142.0 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
| URL | Tags |
|---|---|
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1825621%2C1970079%2C1976736%2C1979072 | Broken Link |
| https://www.mozilla.org/security/advisories/mfsa2025-64/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-70/ | Vendor Advisory |