Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-5264

Опубликовано: 27 мая 2025
Источник: debian
EPSS Низкий

Описание

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed139.0-1package
firefox-esrfixed128.11.0esr-1package
thunderbirdfixed1:128.11.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-42/#CVE-2025-5264

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-44/#CVE-2025-5264

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/#CVE-2025-5264

EPSS

Процентиль: 15%
0.00236
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 1 года назад

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

CVSS3: 6.1
redhat
около 1 года назад

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

CVSS3: 4.8
nvd
около 1 года назад

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

CVSS3: 4.8
github
около 1 года назад

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.

CVSS3: 4.8
fstec
около 1 года назад

Уязвимость функции Copy as cURL браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 15%
0.00236
Низкий