
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14333 is a memory safety vulnerability affecting Mozilla Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. Specifically, it involves memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145, and Thunderbird 145, where some bugs showed evidence of memory corruption that could potentially be exploited to execute arbitrary code. The vulnerability was discovered by Maurice Dauer and the Mozilla Fuzzing Team and disclosed on December 9, 2025. It carries a CVSS v3.1 base score of 8.1 (High) and is rated Moderate severity by Mozilla (Mozilla Advisory mfsa2025-92, Mozilla Advisory mfsa2025-94).
The vulnerability is classified under CWE-787 (Out-of-bounds Write) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), reflecting multiple memory safety bugs discovered through fuzzing. The bugs involve memory corruption in the browser engine components shared across Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145, and Thunderbird 145. Mozilla's advisory notes that while exploitation would require significant effort, the memory corruption evidence suggests arbitrary code execution is theoretically achievable. The underlying bug IDs referenced are 1966501 and 1997639 in Mozilla's Bugzilla (Mozilla Advisory mfsa2025-92, Mozilla Advisory mfsa2025-94).
Successful exploitation of CVE-2025-14333 could allow a remote attacker to execute arbitrary code on affected systems, compromising confidentiality, integrity, and availability. Given the network-based attack vector and the browser/email client context, exploitation could result in full compromise of the user's session, access to sensitive data processed by the browser or email client, and potential for further lateral movement within a network. The CVSS score reflects high impacts across all three security dimensions (Mozilla Advisory mfsa2025-94).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.04%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Mozilla rates the exploitability as requiring significant effort due to the nature of memory safety bugs (Mozilla Advisory mfsa2025-92).
Mozilla has released patched versions addressing CVE-2025-14333: Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird ESR 140.6. Users and administrators should update all affected Mozilla products to these versions or later immediately. No configuration-based workarounds are available; upgrading is the only remediation. Enterprise administrators should prioritize patching Firefox ESR and Thunderbird ESR deployments, as these are commonly used in managed environments (Mozilla Advisory mfsa2025-92, Mozilla Advisory mfsa2025-94).
Multiple Linux distributions including Red Hat, Debian, Oracle Linux, Rocky Linux, AlmaLinux, SUSE, and Slackware issued security advisories and updated packages for Firefox and Thunderbird following Mozilla's disclosure. The CIS (Center for Internet Security) also published an advisory noting that multiple vulnerabilities in Mozilla products could allow for arbitrary code execution. Coverage was largely routine, consistent with Mozilla's regular security release cycle, with no exceptional community alarm given the moderate severity rating and lack of known exploitation (Mozilla Advisory mfsa2025-92).
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.6.0esr-1~deb12u1
sid
thunderbird: 1:140.6.0esr-1
trixie
thunderbird: 1:140.6.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird: 1:140.7.1+build1-0ubuntu0.22.04.1
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."