Логотип exploitDog
bind:"BDU:2025-03142" OR bind:"CVE-2025-0237"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-03142" OR bind:"CVE-2025-0237"

Количество 13

Количество 13

fstec логотип

BDU:2025-03142

около 1 года назад

Уязвимость интерфейса WebChannel API браузеров Mozilla Firefox, Firefox ESR и почтовых клиентов Thunderbird, Thunderbird ESR, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2025-0237

около 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2025-0237

около 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-0237

около 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-0237

около 1 года назад

The WebChannel API, which is used to transport various information acr ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2776-h8x3-vrr7

около 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0080-1

около 1 года назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0059-1

около 1 года назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0056-1

около 1 года назад

Security update for MozillaFirefox

EPSS: Низкий
rocky логотип

RLSA-2025:0144

около 1 года назад

Important: firefox security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0144

около 1 года назад

ELSA-2025-0144: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0132

около 1 года назад

ELSA-2025-0132: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0080

около 1 года назад

ELSA-2025-0080: firefox security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-03142

Уязвимость интерфейса WebChannel API браузеров Mozilla Firefox, Firefox ESR и почтовых клиентов Thunderbird, Thunderbird ESR, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 6.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information acr ...

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2776-h8x3-vrr7

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0080-1

Security update for MozillaThunderbird

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0059-1

Security update for MozillaFirefox

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0056-1

Security update for MozillaFirefox

около 1 года назад
rocky логотип
RLSA-2025:0144

Important: firefox security update

около 1 года назад
oracle-oval логотип
ELSA-2025-0144

ELSA-2025-0144: firefox security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-0132

ELSA-2025-0132: firefox security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-0080

ELSA-2025-0080: firefox security update (IMPORTANT)

около 1 года назад

Уязвимостей на страницу