FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- Out-of-bounds reads and writes

Affected packages
firefox < 144.0.0,2
firefox-esr < 140.4.0
thunderbird < 144.0.0

Details

VuXML ID b760c618-ad02-11f0-b2aa-b42e991fc52e
Discovery 2025-10-14
Entry 2025-10-19

security@mozilla.org reports:

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures.

References

CVE Name CVE-2025-11709
URL https://nvd.nist.gov/vuln/detail/CVE-2025-11709