## This update for MozillaFirefox fixes the following issues: Update to Mozilla Firefox ESR 128.11 (MFSA 2025-44, bsc#1243353): * MFSA-TMP-2025-0001: Double-free in libvpx encoder (bmo#1962421) * CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745) * CVE-2025-5264: Potential local code execution in "Copy as cURL" command (bmo#1950001) * CVE-2025-5265: Potential local code execution in "Copy as cURL" command (bmo#1962301) * CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628) * CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137) * CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139,
* bsc#1243353
Cross-
* CVE-2025-5263
* CVE-2025-5264
* CVE-2025-5265
* CVE-2025-5266
* CVE-2025-5267
* CVE-2025-5268
* CVE-2025-5269
CVSS scores:
* CVE-2025-5263 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2025-5263 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2025-5264 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
* CVE-2025-5264 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
* CVE-2025-5265 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
* CVE-2025-5265 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
* CVE-2025-5266 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-5266 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Get the latest Linux and open source security news straight to your inbox.