VDB
CVE-2025-1020
CVE-2025-1020
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Firefox ist ein Open Source Web Browser. ESR ist die Variante mit verlängertem Support. Thunderbird ist ein Open Source E-Mail Client.
EPSS 0.59% · 69.5th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.59%
69.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Mozilla Firefox ESR <115.20 | |
| Red Hat | Red Hat Enterprise Linux | |
| IGEL | IGEL OS | |
| RESF | RESF Rocky Linux | |
| SUSE | SUSE openSUSE | |
| Oracle | Oracle Linux | |
| Debian | Debian Linux | |
| Mozilla | Mozilla Thunderbird ESR <128.7 | |
| Mozilla | Mozilla Firefox <135 | |
| Gentoo | Gentoo Linux | |
| Amazon | Amazon Linux 2 | |
| Xerox | Xerox FreeFlow Print Server 9 | |
| Mozilla | Mozilla Thunderbird <135 | |
| SUSE | SUSE Linux | |
| Ubuntu | Ubuntu Linux | |
| Mozilla | Mozilla Firefox ESR <128.7 |
Timeline
- Feb 4, 2025 CVE ID Reserved
- Feb 4, 2025 CVE Published
- Feb 5, 2025 EPSS Score
- Feb 8, 2025 Coalition ESS Score
- Feb 18, 2025 Coalition ESS Score
- Feb 20, 2025 EPSS Score
- Mar 7, 2025 EPSS Score
- Mar 21, 2025 EPSS Score
- Apr 5, 2025 EPSS Score
- Apr 20, 2025 EPSS Score
- May 5, 2025 EPSS Score
- May 20, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0262.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0262 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-07/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-08/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-09/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-10/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-11/ advisory
- https://access.redhat.com/errata/RHSA-2025:1066 advisory
- https://linux.oracle.com/errata/ELSA-2025-1066.html advisory
- https://lists.debian.org/debian-security-announce/2025/msg00020.html advisory
- https://access.redhat.com/errata/RHSA-2025:1135 advisory
- https://access.redhat.com/errata/RHSA-2025:1136 advisory
- https://access.redhat.com/errata/RHSA-2025:1137 advisory
- https://access.redhat.com/errata/RHSA-2025:1138 advisory
- https://access.redhat.com/errata/RHSA-2025:1132 advisory
- https://access.redhat.com/errata/RHSA-2025:1133 advisory
- https://access.redhat.com/errata/RHSA-2025:1139 advisory
- https://access.redhat.com/errata/RHSA-2025:1140 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/MP4SZWYCKRN2DG7QYUK64Y4TXD7ABUH5/ advisory
- https://lists.suse.com/pipermail/sle-security-updates/2025-February/020274.html advisory
…and 33 more