VDB
GCVE-110-MAGEIA-2025-168
GCVE-110-MAGEIA-2025-168
Advisory Published
Sender Spoofing via Malformed From Header in Thunderbird.
(CVE-2025-3875)
Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage
via mailbox:/// Links. (CVE-2025-3877)
JavaScript Execution via Spoofed PDF Attachment and file:/// Link.
(CVE-2025-3909)
Tracking Links in Attachments Bypassed Remote Content Blocking.
(CVE-2025-3932)
Out-of-bounds access when resolving Promise objects. (CVE-2025-4918)
Out-of-bounds access when optimizing linear sums. (CVE-2025-4919)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | thunderbird | 128.10.2-1.mga9 (unaffected), 0 (affected) | — |
| Mageia | thunderbird-l10n | 0 (affected), 128.10.2-1.mga9 (unaffected) | — |
Aliases
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.