Логотип exploitDog
bind:CVE-2025-2817
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-2817

Количество 20

Количество 20

ubuntu логотип

CVE-2025-2817

6 месяцев назад

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-2817

6 месяцев назад

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2025-2817

6 месяцев назад

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-2817

6 месяцев назад

Thunderbird's update mechanism allowed a medium-integrity user process ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1414-1

6 месяцев назад

Security update for MozillaFirefox

EPSS: Низкий
github логотип

GHSA-j657-7g4v-wv6h

6 месяцев назад

Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2025-06662

6 месяцев назад

Уязвимость компонента Update Handler браузеров Mozilla Firefox, Mozilla Firefox ESR, почтового клиента Mozilla Thunderbird, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20250710-03

4 месяца назад

Уязвимость Firefox

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2025:4797

3 месяца назад

Important: thunderbird security update

EPSS: Низкий
rocky логотип

RLSA-2025:4458

3 месяца назад

Important: firefox security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7506

4 месяца назад

ELSA-2025-7506: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7428

6 месяцев назад

ELSA-2025-7428: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4797

6 месяцев назад

ELSA-2025-4797: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4751

5 месяцев назад

ELSA-2025-4751: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4460

6 месяцев назад

ELSA-2025-4460: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4458

6 месяцев назад

ELSA-2025-4458: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4443

6 месяцев назад

ELSA-2025-4443: firefox security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1506-1

6 месяцев назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1436-1

6 месяцев назад

Security update for MozillaFirefox

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7507

4 месяца назад

ELSA-2025-7507: thunderbird security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process ...

CVSS3: 8.8
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1414-1

Security update for MozillaFirefox

0%
Низкий
6 месяцев назад
github логотип
GHSA-j657-7g4v-wv6h

Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-06662

Уязвимость компонента Update Handler браузеров Mozilla Firefox, Mozilla Firefox ESR, почтового клиента Mozilla Thunderbird, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
0%
Низкий
6 месяцев назад
redos логотип
ROS-20250710-03

Уязвимость Firefox

CVSS3: 8.8
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2025:4797

Important: thunderbird security update

3 месяца назад
rocky логотип
RLSA-2025:4458

Important: firefox security update

3 месяца назад
oracle-oval логотип
ELSA-2025-7506

ELSA-2025-7506: firefox security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-7428

ELSA-2025-7428: firefox security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2025-4797

ELSA-2025-4797: thunderbird security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2025-4751

ELSA-2025-4751: firefox security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-4460

ELSA-2025-4460: thunderbird security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2025-4458

ELSA-2025-4458: firefox security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2025-4443

ELSA-2025-4443: firefox security update (IMPORTANT)

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1506-1

Security update for MozillaThunderbird

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1436-1

Security update for MozillaFirefox

6 месяцев назад
oracle-oval логотип
ELSA-2025-7507

ELSA-2025-7507: thunderbird security update (IMPORTANT)

4 месяца назад

Уязвимостей на страницу