Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4083

Опубликовано: 29 апр. 2025
Источник: debian
EPSS Низкий

Описание

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed138.0-1package
firefox-esrfixed128.10.0esr-1package
thunderbirdfixed1:128.10.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-28/#CVE-2025-4083

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-29/#CVE-2025-4083

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-32/#CVE-2025-4083

EPSS

Процентиль: 17%
0.00053
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.3
redhat
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 9.1
nvd
около 2 месяцев назад

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 9.1
github
около 2 месяцев назад

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.

CVSS3: 9.1
redos
3 дня назад

Множественные уязвимости firefox

EPSS

Процентиль: 17%
0.00053
Низкий