VDB
GCVE-VVD-NCSC-2025-325
GCVE-VVD-NCSC-2025-325
Advisory PublishedCVSS 9.8/10
A use-after-free vulnerability in MediaTrackGraphImpl::GetInstance() affects Firefox and Thunderbird versions below 144, with specific ESR versions also impacted, as assessed by Red Hat Product Security.
Weaknesses (CWE)
CWE-416Use After FreeCWE-125Out-of-bounds ReadCWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-284Improper Access ControlCWE-436Interpretation ConflictCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-119Improper Restriction of Operations within the Bounds of a Memory BufferCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-451User Interface (UI) Misrepresentation of Critical Information
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mozilla | vers:unknown/* | — | — |
Aliases
CVE-2025-11711CVE-2025-11710CVE-2025-11709CVE-2025-11721CVE-2025-11716CVE-2025-11717CVE-2025-11712CVE-2025-11718CVE-2025-11719CVE-2025-11713CVE-2025-11708CVE-2025-11720CVE-2025-11714CVE-2025-11715
Transitive aliases
VVD-ANCHORE-2025-10535GHSA-2w9w-fgq6-2vmcALSA-2025:18321CVE-2025-10528VVD-ANCHORE-2025-10529CVE-2025-13024VVD-ANCHORE-2025-13016GHSA-hmr9-3q48-52hrBDU:2025-13289GHSA-74x5-q3v4-qjxxBDU:2025-14547CNVD-2025-24634BDU:2025-14508GHSA-pwc5-5wfj-q75cCVE-2025-10532SUSE-SU-2025:03291-1CNVD-2025-24652VVD-MAGEIA-2025-305CVE-2025-10527ALSA-2025:16108OPENSUSE-SU-2025:20021-1GHSA-9qv5-m6vr-vh73VVD-ANCHORE-2025-10537ALSA-2025:18155GHSA-hjv3-x37x-j8jmWID-SEC-W-2025-2275RHSA-2025:17345OPENSUSE-SU-2025:15555-1BDU:2025-11383CVE-2025-13027BDU:2025-14545VVD-ANCHORE-2025-13026RHSA-2025:17340GHSA-gwf4-vcvc-4rjvBDU:2025-14510VVD-ANCHORE-2025-11712CVE-2025-13013CVE-2025-13015BDU:2025-14544CVE-2025-10536VVD-ANCHORE-2025-10532BDU:2025-13292VVD-ANCHORE-2025-11709CNVD-2025-24620RHSA-2025:16260RHSA-2025:17372CNVD-2025-24636GHSA-wjhw-rxqj-2g2hVVD-ANCHORE-2025-10533CVE-2025-13019BDU:2025-11384ALSA-2025:21881VVD-ANCHORE-2025-13012BDU:2025-11334OPENSUSE-SU-2025:20065-1GHSA-h7jc-cc8w-wcwgGHSA-2p9h-v8v8-2j3wALSA-2025:16260GHSA-f2wr-3fjg-j32fGHSA-pww6-475j-f225CVE-2025-10290VVD-ANCHORE-2025-10527VVD-ANCHORE-2025-11708RHSA-2025:16589BDU:2025-11378BDU:2025-14550VVD-ANCHORE-2025-10530GHSA-rf6g-cf9f-g4v7VVD-ANCHORE-2025-11714RHSA-2025:17371GHSA-5qj7-cv36-4gxhCNVD-2025-24651VVD-ANCHORE-2025-13019RHSA-2025:17373GHSA-2w7r-ggfp-x894BDU:2025-14509CVE-2025-13018NCSC-2025-0325OPENSUSE-SU-2025-20021-1OPENSUSE-SU-2025:15735-1ALSA-2025:22363VVD-ANCHORE-2025-13015GHSA-v5ww-rww6-gq76ALSA-2025:21281GHSA-8q64-5xmq-2f45VVD-ANCHORE-2025-13014CVE-2025-10530VVD-MAGEIA-2025-300VVD-ANCHORE-2025-13023VVD-ANCHORE-2025-11710GHSA-cqj3-wx7w-jfx6BDU:2025-14553CVE-2025-13014OPENSUSE-SU-2025:15560-1BDU:2025-11381CNVD-2025-26890CNVD-2025-28722GHSA-mv5g-cf64-38cvVVD-ANCHORE-2025-11715RHSA-2025:16157ALSA-2025:18285BDU:2025-11332VVD-ANCHORE-2025-13024WID-SEC-W-2025-2074ALSA-2025:16156GHSA-jcc8-69x6-295gGHSA-vpvq-m4pf-x2cpALSA-2025:21280VVD-ANCHORE-2025-10534VVD-ANCHORE-2025-13025OPENSUSE-SU-2025-20065-1VVD-ANCHORE-2025-11713CVE-2025-13021GHSA-v7r3-hxvj-7w2pCNVD-2025-24637RHSA-2025:17341CVE-2025-10531SUSE-SU-2025:03287-1GHSA-5vxr-wr7m-x3p3GHSA-ff52-484q-63r5GHSA-wvmm-cxmc-39xjGHSA-vcwp-4m7w-hxfhSUSE-SU-2025:21021-1BDU:2025-11377GHSA-75p5-w5j4-v8qjCVE-2025-10529CVE-2025-13012VVD-ANCHORE-2025-10536VVD-MAGEIA-2025-246CVE-2025-13016RHSA-2025:16156RHSA-2025:17342BDU:2025-11379VVD-ANCHORE-2025-13013GHSA-63qq-765j-587xRHSA-2025:17344CVE-2025-13022GHSA-8prr-wp36-5mv2CNVD-2025-24639GHSA-mqxv-fv77-3585BDU:2025-13250VVD-ANCHORE-2025-11716GHSA-579p-jcg6-h5r2CVE-2025-13025VVD-ANCHORE-2025-13020ALSA-2025:16589BDU:2025-11380CNVD-2025-24653VVD-MAGEIA-2025-247RHSA-2025:17374BDU:2025-11382GHSA-2q3p-f6j6-9qhjBDU:2025-14087CNVD-2025-28723VVD-ANCHORE-2025-11711CVE-2025-13017CVE-2025-13020RHSA-2025:17343RHSA-2025:16108GHSA-ghxv-675w-53v8BDU:2025-14554GHSA-pvxc-5v6m-8cm2VVD-ANCHORE-2025-13017VVD-ANCHORE-2025-13018GHSA-53qc-r462-795hRHSA-2025:17367CNVD-2025-24629GHSA-wjv8-8vf9-mrv8CNVD-2025-24638BDU:2025-14552GHSA-p2g2-wp3h-q672VVD-ANCHORE-2025-10531GHSA-p8g8-q63w-8jgmCVE-2025-10533CVE-2025-10534ALSA-2025:16109BDU:2025-14549CNVD-2025-24635GHSA-hjm2-5w4g-m8j2GHSA-h6qg-7fq8-gw5hVVD-ANCHORE-2025-13021ALSA-2025:18983BDU:2025-13249CNVD-2025-26891GHSA-r25g-xjc5-pcrvCVE-2025-10535SUSE-SU-2025:03309-1OPENSUSE-SU-2025:15565-1BDU:2025-14548CNVD-2025-28720BDU:2025-14538RHSA-2025:17368RHSA-2025:17378RHSA-2025:17453VVD-ANCHORE-2025-10528GHSA-xp5g-gff9-qvvxALSA-2025:18320BDU:2025-13293BDU:2025-13294ALSA-2025:21843VVD-ANCHORE-2025-13027CNVD-2025-24646WID-SEC-W-2025-2566CVE-2025-13026RHSA-2025:17346CVE-2025-13023BDU:2025-14551BDU:2025-14088BDU:2025-13290BDU:2025-13288CVE-2025-10537CNVD-2025-28721BDU:2025-13291RHSA-2025:16109BDU:2025-11333VVD-ANCHORE-2025-10290BDU:2025-14085VVD-ANCHORE-2025-13022BDU:2025-14086OPENSUSE-SU-2025:15645-1ALSA-2025:18154ALSA-2025:16157BDU:2025-14546
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.