VDB

GCVE-110-MAGEIA-2025-246

GCVE-110-MAGEIA-2025-246
Advisory Published
Vulnetix · Advisory published October 23, 2025
CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures CVE-2025-11710: Cross-process information leaked due to malicious IPC messages CVE-2025-11711: Some non-writable Object properties could be modified CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144, and other security fixes; please see the links.

Affected Products

VendorProductVersionsPlatforms
Mageiafirefox140.4.0-1.2.mga9 (unaffected), 0 (affected)
Mageiafirefox-l10n140.4.0-1.mga9 (unaffected), 0 (affected)
Mageiarootcerts0 (affected), 20251003.00-1.mga9 (unaffected)
Mageianss0 (affected), 3.117.0-1.mga9 (unaffected)

Browse GCVE Records

75,875 records in the GCVE database · Updated August 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›