Metrics
Affected Vendors & Products
Tue, 19 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This CVE was accidentally assigned by Mozilla but should be assigned by another CNA. When the correct CVE is available, Mozilla's advisories will be updated to reflect that identifier. | A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11. |
References |
|
Thu, 29 May 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | firefox: thunderbird: Double-free in libvpx encoder | |
Weaknesses | CWE-415 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 27 May 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-415 | |
References |
|
|
Metrics |
cvssV3_1
|
Tue, 27 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 27 May 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. | This CVE was accidentally assigned by Mozilla but should be assigned by another CNA. When the correct CVE is available, Mozilla's advisories will be updated to reflect that identifier. |
Tue, 27 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-415 | |
Metrics |
cvssV3_1
|
Tue, 27 May 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. | |
References |
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-05-27T12:29:21.813Z
Updated: 2025-08-19T20:52:45.713Z
Reserved: 2025-05-27T12:29:21.325Z
Link: CVE-2025-5262

Updated: 2025-05-27T15:33:14.225Z

Status : Awaiting Analysis
Published: 2025-05-27T13:15:21.980
Modified: 2025-08-20T14:40:17.713
Link: CVE-2025-5262
