Количество 13
Количество 13
GHSA-78fw-w53r-pgwg
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to ...
BDU:2025-06555
Уязвимость почтового клиента Thunderbird, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес
SUSE-SU-2025:1366-1
Security update for MozillaThunderbird
ROS-20250515-08
Множественные уязвимости thunderbird
RLSA-2025:7435
Important: thunderbird security update
ELSA-2025-7435
ELSA-2025-7435: thunderbird security update (IMPORTANT)
ELSA-2025-4649
ELSA-2025-4649: thunderbird security update (IMPORTANT)
ELSA-2025-4229
ELSA-2025-4229: thunderbird security update (IMPORTANT)
ELSA-2025-7507
ELSA-2025-7507: thunderbird security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-78fw-w53r-pgwg Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3522 Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3522 Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
CVE-2025-3522 Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3522 Thunderbird processes the X-Mozilla-External-Attachment-URL header to ... | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
BDU:2025-06555 Уязвимость почтового клиента Thunderbird, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
SUSE-SU-2025:1366-1 Security update for MozillaThunderbird | больше 1 года назад | |||
ROS-20250515-08 Множественные уязвимости thunderbird | CVSS3: 6.4 | около 1 года назад | ||
RLSA-2025:7435 Important: thunderbird security update | около 1 года назад | |||
ELSA-2025-7435 ELSA-2025-7435: thunderbird security update (IMPORTANT) | около 1 года назад | |||
ELSA-2025-4649 ELSA-2025-4649: thunderbird security update (IMPORTANT) | около 1 года назад | |||
ELSA-2025-4229 ELSA-2025-4229: thunderbird security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2025-7507 ELSA-2025-7507: thunderbird security update (IMPORTANT) | около 1 года назад |
Уязвимостей на страницу