Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-5263

Опубликовано: 27 мая 2025
Источник: debian
EPSS Низкий

Описание

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed139.0-1package
firefox-esrfixed128.11.0esr-1package
thunderbirdfixed1:128.11.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-42/#CVE-2025-5263

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-44/#CVE-2025-5263

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/#CVE-2025-5263

EPSS

Процентиль: 8%
0.00033
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

CVSS3: 6.1
redhat
2 месяца назад

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

CVSS3: 4.3
nvd
2 месяца назад

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

CVSS3: 4.3
github
2 месяца назад

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.

CVSS3: 4.3
fstec
2 месяца назад

Уязвимость механизма CORS браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 8%
0.00033
Низкий