CVE-2025-5262 describes a double-free vulnerability in the vpx_codec_enc_init_multi function within Thunderbird, affecting versions prior to 139 and 128.11. This flaw, stemming from a failed memory allocation during WebRTC encoder initialization, could lead to memory corruption and a potentially exploitable crash. Rated 7.5 HIGH on CVSS, it is a network-exploitable vulnerability with low attack complexity, posing a high impact to availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 128.11.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* | ||
< 139.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* | ||
< 128.11CPE match | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
< 139CPE match | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.