VDB

GCVE-110-MAGEIA-2025-168

GCVE-110-MAGEIA-2025-168
Advisory Published
Vulnetix · Advisory published May 27, 2025
Sender Spoofing via Malformed From Header in Thunderbird. (CVE-2025-3875) Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links. (CVE-2025-3877) JavaScript Execution via Spoofed PDF Attachment and file:/// Link. (CVE-2025-3909) Tracking Links in Attachments Bypassed Remote Content Blocking. (CVE-2025-3932) Out-of-bounds access when resolving Promise objects. (CVE-2025-4918) Out-of-bounds access when optimizing linear sums. (CVE-2025-4919)

Affected Products

VendorProductVersionsPlatforms
Mageiathunderbird128.10.2-1.mga9 (unaffected), 0 (affected)
Mageiathunderbird-l10n0 (affected), 128.10.2-1.mga9 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›