Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
Security Fix(es):
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise
object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.(CVE-2025-4918)
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.(CVE-2025-4919)
{ "severity": "High" }
{ "src": [ "firefox-128.10.1-1.oe2203sp4.src.rpm" ], "x86_64": [ "firefox-128.10.1-1.oe2203sp4.x86_64.rpm", "firefox-debuginfo-128.10.1-1.oe2203sp4.x86_64.rpm", "firefox-debugsource-128.10.1-1.oe2203sp4.x86_64.rpm" ], "aarch64": [ "firefox-128.10.1-1.oe2203sp4.aarch64.rpm", "firefox-debuginfo-128.10.1-1.oe2203sp4.aarch64.rpm", "firefox-debugsource-128.10.1-1.oe2203sp4.aarch64.rpm" ] }