Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4087

Опубликовано: 29 апр. 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed138.0-1package
firefox-esrfixed128.10.0esr-1package
thunderbirdfixed1:128.10.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-28/#CVE-2025-4087

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-29/#CVE-2025-4087

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-32/#CVE-2025-4087

EPSS

Процентиль: 21%
0.00068
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 7.6
redhat
около 2 месяцев назад

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 6.5
nvd
около 2 месяцев назад

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 6.5
github
около 2 месяцев назад

A vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.

CVSS3: 6.5
fstec
около 2 месяцев назад

Уязвимость браузеров Mozilla Firefox и Firefox ESR, почтового клиента Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 21%
0.00068
Низкий