6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Description
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Basic Information
ID
CVE-2025-8027
Source
mozilla
Published
Jul 22, 2025 at 20:49
Modified
Jul 23, 2025 at 13:46
Affected Product
Vendor
Mozilla
Product
Firefox
Version
unspecified
Affected Versions
Mozilla Firefox unspecified
Mozilla Firefox ESR unspecified
Mozilla Firefox ESR unspecified
Mozilla Firefox ESR unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
Mozilla Firefox ESR unspecified
Mozilla Firefox ESR unspecified
Mozilla Firefox ESR unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
CWE Classification
References
- bugzilla.mozilla.org /show_bug.cgi
- www.mozilla.org /security/advisories/mfsa2025-56/
- www.mozilla.org /security/advisories/mfsa2025-57/
- www.mozilla.org /security/advisories/mfsa2025-58/
- www.mozilla.org /security/advisories/mfsa2025-59/
- www.mozilla.org /security/advisories/mfsa2025-61/
- www.mozilla.org /security/advisories/mfsa2025-62/
- www.mozilla.org /security/advisories/mfsa2025-63/