9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
AI Analysis
Use-after-free vulnerability in the WebRTC: Signaling component of Firefox and Thunderbird
Basic Information
ID
CVE-2025-14321
Source
mozilla
Published
Dec 9, 2025 at 13:37
Modified
Dec 11, 2025 at 20:36
Affected Product
Vendor
Mozilla
Product
Firefox
Version
unspecified
Affected Versions
Mozilla Firefox unspecified
Mozilla Firefox ESR unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
Mozilla Firefox ESR unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Mozilla
Product
Firefox, Thunderbird
Version
< 146, < 140.6