Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-4086

Опубликовано: 29 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected. This vulnerability affects Firefox < 138 and Thunderbird < 138.

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

android only
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

code not present
upstream

not-affected

debian: Only affects Firefox on Android

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

android only
jammy

not-affected

android only
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

code not present
upstream

needs-triage

Показывать по

EPSS

Процентиль: 13%
0.00043
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
около 2 месяцев назад

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

CVSS3: 6.5
nvd
около 2 месяцев назад

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

CVSS3: 6.5
debian
около 2 месяцев назад

A specially crafted filename containing a large number of encoded newl ...

CVSS3: 6.5
github
около 2 месяцев назад

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

EPSS

Процентиль: 13%
0.00043
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2025-4086