VDB

DEBIAN-CVE-2025-4083

DEBIAN-CVE-2025-4083 PUBLISHED CVSS 9.100000381469727 CRITICAL

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Debian:11firefox-esr115.9.0, 115.9.1, 115.9.1
Debian:14thunderbird0, 0
Debian:14firefox-esr0, 0
Debian:13firefox-esr0, 0
Debian:13thunderbird0, 0
Debian:12firefox-esr0, *, 128.9.0esr-2
Debian:11thunderbird91.2.1-1, 1:102.0.1-1, 1:102.0.2-1
Debian:12thunderbird*, *, *

Timeline

  • Apr 29, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›