CVE-2025-11708

Description

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.082

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Mozilla Firefox ESR (140) (140.4.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox ESR (140) (x64) (140.4.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (x64) (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird ESR 140 (140.4.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird ESR 140 (x64) (140.4.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird (x64) (144.0)Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 140.3.9Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 143.9Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 140.3.99Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 143.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 140.3.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 143.99Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (144.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (144.0.2)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352420Mozilla Firefox ESR (140) (140.4.0)
PATCH-352421Mozilla Firefox ESR (140) (x64) (140.4.0)
PATCH-352416Mozilla Firefox (144.0)
PATCH-352417Mozilla Firefox (x64) (144.0)
PATCH-352422Mozilla Thunderbird ESR 140 (140.4.0)
PATCH-352423Mozilla Thunderbird ESR 140 (x64) (140.4.0)
PATCH-352439Mozilla Thunderbird (144.0)
PATCH-352440Mozilla Thunderbird (x64) (144.0)
PATCH-613630Mozilla Firefox For Mac (147.0.4)
PATCH-613630Mozilla Firefox For Mac (147.0.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234