Логотип exploitDog
bind:"GHSA-g6gh-87cw-x396" OR bind:"CVE-2025-2830"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-g6gh-87cw-x396" OR bind:"CVE-2025-2830"

Количество 11

Количество 11

github логотип

GHSA-g6gh-87cw-x396

2 месяца назад

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2025-2830

2 месяца назад

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2025-2830

2 месяца назад

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-2830

2 месяца назад

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2025-2830

2 месяца назад

By crafting a malformed file name for an attachment in a multipart mes ...

CVSS3: 6.3
EPSS: Низкий
fstec логотип

BDU:2025-06569

2 месяца назад

Уязвимость почтового клиента Thunderbird, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1366-1

около 2 месяцев назад

Security update for MozillaThunderbird

EPSS: Низкий
redos логотип

ROS-20250515-08

около 1 месяца назад

Множественные уязвимости thunderbird

CVSS3: 6.4
EPSS: Низкий
oracle-oval логотип

ELSA-2025-7435

29 дней назад

ELSA-2025-7435: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4649

около 1 месяца назад

ELSA-2025-4649: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4229

около 2 месяцев назад

ELSA-2025-4229: thunderbird security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g6gh-87cw-x396

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.3
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.3
0%
Низкий
2 месяца назад
redhat логотип
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.

CVSS3: 6.3
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart mes ...

CVSS3: 6.3
0%
Низкий
2 месяца назад
fstec логотип
BDU:2025-06569

Уязвимость почтового клиента Thunderbird, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.3
0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:1366-1

Security update for MozillaThunderbird

около 2 месяцев назад
redos логотип
ROS-20250515-08

Множественные уязвимости thunderbird

CVSS3: 6.4
около 1 месяца назад
oracle-oval логотип
ELSA-2025-7435

ELSA-2025-7435: thunderbird security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2025-4649

ELSA-2025-4649: thunderbird security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2025-4229

ELSA-2025-4229: thunderbird security update (IMPORTANT)

около 2 месяцев назад

Уязвимостей на страницу