Логотип exploitDog
bind:"BDU:2025-10491" OR bind:"CVE-2025-8037"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-10491" OR bind:"CVE-2025-8037"

Количество 9

Количество 9

fstec логотип

BDU:2025-10491

около 2 месяцев назад

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с отсутствием флага «Secure» в файлах cookie HTTPS-сеанса, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2025-8037

около 2 месяцев назад

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2025-8037

около 2 месяцев назад

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-8037

около 2 месяцев назад

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2025-8037

около 2 месяцев назад

Setting a nameless cookie with an equals sign in the value shadowed ot ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-fw75-5frq-vxhg

около 2 месяцев назад

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02531-1

около 2 месяцев назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02546-1

около 2 месяцев назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02529-1

около 2 месяцев назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-10491

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с отсутствием флага «Secure» в файлах cookie HTTPS-сеанса, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed ot ...

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-fw75-5frq-vxhg

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02531-1

Security update for MozillaFirefox

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02546-1

Security update for MozillaThunderbird

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02529-1

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

около 2 месяцев назад

Уязвимостей на страницу