Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

ubuntu логотип

CVE-2025-3909

около 1 года назад

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2025-3909

около 1 года назад

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-3909

около 1 года назад

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-3909

около 1 года назад

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h6cg-6m9j-xj9g

около 1 года назад

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-05734

около 1 года назад

Уязвимость почтового клиента Thunderbird, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01660-2

около 1 года назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01660-1

около 1 года назад

Security update for MozillaThunderbird

EPSS: Низкий
rocky логотип

RLSA-2025:8203

10 месяцев назад

Important: thunderbird security update

EPSS: Низкий
rocky логотип

RLSA-2025:8196

10 месяцев назад

Important: thunderbird security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8203

около 1 года назад

ELSA-2025-8203: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8196

около 1 года назад

ELSA-2025-8196: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8756

около 1 года назад

ELSA-2025-8756: thunderbird security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2025:8756

около 1 года назад

Important: thunderbird security update

EPSS: Низкий
redos логотип

ROS-20250703-08

около 1 года назад

Множественные уязвимости Thunderbird

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-3909

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

CVSS3: 8.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-3909

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-3909

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

CVSS3: 8.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-3909

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header ...

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-h6cg-6m9j-xj9g

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-05734

Уязвимость почтового клиента Thunderbird, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01660-2

Security update for MozillaThunderbird

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01660-1

Security update for MozillaThunderbird

около 1 года назад
rocky логотип
RLSA-2025:8203

Important: thunderbird security update

10 месяцев назад
rocky логотип
RLSA-2025:8196

Important: thunderbird security update

10 месяцев назад
oracle-oval логотип
ELSA-2025-8203

ELSA-2025-8203: thunderbird security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-8196

ELSA-2025-8196: thunderbird security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-8756

ELSA-2025-8756: thunderbird security update (IMPORTANT)

около 1 года назад
rocky логотип
RLSA-2025:8756

Important: thunderbird security update

около 1 года назад
redos логотип
ROS-20250703-08

Множественные уязвимости Thunderbird

CVSS3: 7.5
около 1 года назад

Уязвимостей на страницу