Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
Security Fix(es):
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.(CVE-2025-4918)
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.(CVE-2025-4919)
{
"severity": "High"
}{
"src": [
"firefox-128.10.1-1.oe2203sp3.src.rpm"
],
"aarch64": [
"firefox-128.10.1-1.oe2203sp3.aarch64.rpm",
"firefox-debuginfo-128.10.1-1.oe2203sp3.aarch64.rpm",
"firefox-debugsource-128.10.1-1.oe2203sp3.aarch64.rpm"
],
"x86_64": [
"firefox-128.10.1-1.oe2203sp3.x86_64.rpm",
"firefox-debuginfo-128.10.1-1.oe2203sp3.x86_64.rpm",
"firefox-debugsource-128.10.1-1.oe2203sp3.x86_64.rpm"
]
}