Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-1935

Опубликовано: 04 мар. 2025
Источник: debian

Описание

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed136.0-1package
firefox-esrfixed128.8.0esr-1package
thunderbirdfixed1:128.8.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-14/#CVE-2025-1935

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-16/#CVE-2025-1935

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-18/#CVE-2025-1935

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVSS3: 4.3
redhat
4 месяца назад

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVSS3: 4.3
nvd
4 месяца назад

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVSS3: 4.3
github
4 месяца назад

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 4.3
fstec
4 месяца назад

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, Thunderbird ESR, связанная с ошибками представления информации пользовательским интерфейсом, позволяющая нарушителю оказать влияние на целостность защищаемой информации