VDB
WID-SEC-W-2025-1866
WID-SEC-W-2025-1866
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Firefox ist ein Open Source Web Browser. ESR ist die Variante mit verlängertem Support. Thunderbird ist ein Open Source E-Mail Client.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla Firefox ESR 115.27 | ||
| Mozilla Thunderbird <128.14 | ||
| Mozilla Firefox 142 | ||
| Mozilla Firefox ESR 140.2 | ||
| Mozilla Firefox iOS 142 | ||
| Amazon Linux 2 | ||
| Mozilla Firefox <142 | ||
| Mozilla Firefox ESR <140.2 | ||
| Mozilla Firefox iOS <142 | ||
| IGEL OS | ||
| Mozilla Thunderbird 142 | ||
| Mozilla Firefox ESR <115.27 | ||
| Mozilla Firefox ESR 128.14 | ||
| Oracle Linux | ||
| Debian Linux | ||
| Mozilla Thunderbird 140.2 | ||
| Mozilla Thunderbird 128.14 | ||
| Mozilla Thunderbird <142 | ||
| Mozilla Firefox ESR <128.14 | ||
| Mozilla Thunderbird <140.2 |
Exploit Intelligence
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1866.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1866 (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-64/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-65/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-66/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-67/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-68/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-69/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-70/ (circl)
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-71/ (circl)
…and 53 more exploits
Timeline
- Aug 19, 2025 CVE Published
- Oct 23, 2025 CVE Updated
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
- Apr 22, 2026 Distribution Patch
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1866.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1866 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-64/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-65/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-66/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-67/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-68/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-69/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-70/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-71/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-72/ url
- https://lists.debian.org/debian-security-announce/2025/msg00144.html url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7ZG3O2VY7KOKS72KN6VW4LMQYP2C6RLE/ url
- https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html url
- https://lists.debian.org/debian-security-announce/2025/msg00148.html url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYYOHEMZQQSD7I3AJFGAMV3O3PPYP2MS/ url
- https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html url
- https://access.redhat.com/errata/RHSA-2025:14416 url
- https://access.redhat.com/errata/RHSA-2025:14417 url
- https://access.redhat.com/errata/RHSA-2025:14442 url
…and 43 more