Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-4086

Опубликовано: 29 апр. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected. This vulnerability affects Firefox < 138 and Thunderbird < 138.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
Версия до 138.0 (исключая)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
Версия до 138.0 (исключая)

EPSS

Процентиль: 13%
0.00045
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-451

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

CVSS3: 5.4
redhat
3 месяца назад

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

CVSS3: 6.5
debian
3 месяца назад

A specially crafted filename containing a large number of encoded newl ...

CVSS3: 6.5
github
3 месяца назад

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

EPSS

Процентиль: 13%
0.00045
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-451