FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- exploitable crash

Affected packages
firefox < 140.0,2
firefox-esr < 115.25.0
thunderbird < 140.0

Details

VuXML ID bab7386a-582f-11f0-97d0-b42e991fc52e
Discovery 2025-06-24
Entry 2025-07-03

security@mozilla.org reports:

A use-after-free in FontFaceSet resulted in a potentially exploitable crash.

References

CVE Name CVE-2025-6424
URL https://nvd.nist.gov/vuln/detail/CVE-2025-6424