fkie_cve-2025-5262
Vulnerability from fkie_nvd
Published
2025-05-27 13:15
Modified
2025-08-20 14:40
Severity ?
Summary
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
References
Impacted products
Vendor | Product | Version |
---|
{ "cveTags": [], "descriptions": [ { "lang": "en", "value": "A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird \u003c 139 and Thunderbird \u003c 128.11." }, { "lang": "es", "value": "Podr\u00eda haberse producido una doble liberaci\u00f3n en `vpx_codec_enc_init_multi` tras un error de asignaci\u00f3n al inicializar el codificador para WebRTC. Esto podr\u00eda haber causado corrupci\u00f3n de memoria y un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Thunderbird (versi\u00f3n anterior a la 139) y Thunderbird (versi\u00f3n anterior a la 128.11)." } ], "id": "CVE-2025-5262", "lastModified": "2025-08-20T14:40:17.713", "metrics": {}, "published": "2025-05-27T13:15:21.980", "references": [ { "source": "security@mozilla.org", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1962421" }, { "source": "security@mozilla.org", "url": "https://www.mozilla.org/security/advisories/mfsa2025-45/" }, { "source": "security@mozilla.org", "url": "https://www.mozilla.org/security/advisories/mfsa2025-46/" } ], "sourceIdentifier": "security@mozilla.org", "vulnStatus": "Awaiting Analysis" }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…