VDB

DEBIAN-CVE-2025-0237

DEBIAN-CVE-2025-0237 PUBLISHED CVSS 5.400000095367432 MEDIUM

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:12firefox-esr*, *, *
Debian:12thunderbird115.8.0-1, 115.8.0-1, 115.8.0-1
Debian:13firefox-esr0, 0
Debian:14thunderbird0, 0
Debian:13thunderbird0, 0
Debian:11thunderbird1:91.6.1-1~deb10u1, 1:91.6.1-1~deb11u1, 1:91.6.1-1~deb9u1
Debian:14firefox-esr0, 0
Debian:11firefox-esr102.14.0, 102.14.0, 102.14.0

Exploit Intelligence

Timeline

  • Jan 7, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›