Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and Thunderbird < 128.6.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0238.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "115.19.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "134.0"
}
]
},
{
"events": [
{
"introduced": "116.0"
},
{
"fixed": "128.6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "128.6"
}
]
},
{
"events": [
{
"introduced": "129.0"
},
{
"fixed": "134.0"
}
]
}
]