Security update for MozillaFirefox
This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.4.0 ESR (bsc#1251263). - CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() - CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures - CVE-2025-11710: Cross-process information leaked due to malicious IPC messages - CVE-2025-11711: Some non-writable Object properties could be modified - CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type - CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command - CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 - CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.4.0 ESR (bsc#1251263). - CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() - CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures - CVE-2025-11710: Cross-process information leaked due to malicious IPC messages - CVE-2025-11711: Some non-writable Object properties could be modified - CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type - CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command - CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 - CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1251263
- https://www.suse.com/security/cve/CVE-2025-11708
- https://www.suse.com/security/cve/CVE-2025-11709
- https://www.suse.com/security/cve/CVE-2025-11710
- https://www.suse.com/security/cve/CVE-2025-11711
- https://www.suse.com/security/cve/CVE-2025-11712
- https://www.suse.com/security/cve/CVE-2025-11713
- https://www.suse.com/security/cve/CVE-2025-11714
- https://www.suse.com/security/cve/CVE-2025-11715
- https://www.suse.com/support/update/announcement/2025/suse-su-20253775-1/