Логотип exploitDog
bind:CVE-2025-3932
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3932

Количество 14

Количество 14

ubuntu логотип

CVE-2025-3932

6 месяцев назад

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2025-3932

6 месяцев назад

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-3932

6 месяцев назад

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-3932

6 месяцев назад

It was possible to craft an email that showed a tracking link as an at ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jfxg-6gv4-f2gh

6 месяцев назад

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-08557

6 месяцев назад

Уязвимость почтового клиента Thunderbird, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01660-2

5 месяцев назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01660-1

6 месяцев назад

Security update for MozillaThunderbird

EPSS: Низкий
rocky логотип

RLSA-2025:8196

около 1 месяца назад

Important: thunderbird security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8203

5 месяцев назад

ELSA-2025-8203: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8196

4 месяца назад

ELSA-2025-8196: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8756

5 месяцев назад

ELSA-2025-8756: thunderbird security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2025:8756

3 месяца назад

Important: thunderbird security update

EPSS: Низкий
redos логотип

ROS-20250703-08

4 месяца назад

Множественные уязвимости Thunderbird

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-3932

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-3932

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-3932

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-3932

It was possible to craft an email that showed a tracking link as an at ...

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-jfxg-6gv4-f2gh

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-08557

Уязвимость почтового клиента Thunderbird, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01660-2

Security update for MozillaThunderbird

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01660-1

Security update for MozillaThunderbird

6 месяцев назад
rocky логотип
RLSA-2025:8196

Important: thunderbird security update

около 1 месяца назад
oracle-oval логотип
ELSA-2025-8203

ELSA-2025-8203: thunderbird security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-8196

ELSA-2025-8196: thunderbird security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-8756

ELSA-2025-8756: thunderbird security update (IMPORTANT)

5 месяцев назад
rocky логотип
RLSA-2025:8756

Important: thunderbird security update

3 месяца назад
redos логотип
ROS-20250703-08

Множественные уязвимости Thunderbird

CVSS3: 7.5
4 месяца назад

Уязвимостей на страницу