Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5g22-6w6r-pr2m

Опубликовано: 22 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

EPSS

Процентиль: 34%
0.00417
Низкий

8.1 High

CVSS3

Дефекты

CWE-350

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 года назад

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

CVSS3: 6.1
redhat
около 1 года назад

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

CVSS3: 8.1
nvd
около 1 года назад

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

CVSS3: 8.1
debian
около 1 года назад

Thunderbird cached CORS preflight responses across IP address changes. ...

CVSS3: 8.1
fstec
около 1 года назад

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с зависимостью критичных действий от обратного DNS-решения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 34%
0.00417
Низкий

8.1 High

CVSS3

Дефекты

CWE-350