CVE-2025-49709
BaseFortify
Publication date: 2025-06-11
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | From 60.9.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
Certain canvas operations in Firefox versions prior to 139.0.4 could lead to memory corruption, which means that improper handling of memory during these operations might cause the program to behave unexpectedly or crash.
How can this vulnerability impact me? :
This vulnerability could cause Firefox to crash or behave unpredictably when performing certain canvas operations, potentially leading to denial of service or other security issues related to memory corruption.
What immediate steps should I take to mitigate this vulnerability?
Update Firefox to version 139.0.4 or later, as this version contains the fix for the memory corruption vulnerability related to certain canvas operations. [1]