CVE-2025-5262
27.05.2025, 13:15
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | thunderbird | 𝑥 < 128.11.0 |
mozilla | thunderbird | 𝑥 < 139.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
thunderbird |
| ||||||||||||
mozjs38 |
| ||||||||||||
mozjs52 |
| ||||||||||||
mozjs68 |
| ||||||||||||
mozjs78 |
| ||||||||||||
mozjs91 |
| ||||||||||||
mozjs102 |
| ||||||||||||
mozjs115 |
|
Common Weakness Enumeration