Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-5266

Опубликовано: 27 мая 2025
Источник: debian
EPSS Низкий

Описание

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed139.0-1package
firefox-esrfixed128.11.0esr-1package
thunderbirdfixed1:128.11.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-42/#CVE-2025-5266

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-44/#CVE-2025-5266

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/#CVE-2025-5266

EPSS

Процентиль: 21%
0.00068
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

CVSS3: 6.1
redhat
2 месяца назад

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

CVSS3: 6.5
nvd
2 месяца назад

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.

CVSS3: 6.5
github
2 месяца назад

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 6.5
fstec
2 месяца назад

Уязвимость механизма CORS браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 21%
0.00068
Низкий