V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-8038
ANC
Critical

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140…

CVSS
9.8
Critical
EPSS
0.00
p12
Published
2025-01-01
Updated
2025-01-01
Description

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

Tags · CWE
Pre-auth
CWE-345
CWE-693
CAPEC-1
CAPEC-17
CAPEC-20
CAPEC-22
CAPEC-36
CAPEC-51
CAPEC-57
CAPEC-59
CAPEC-65
CAPEC-74
CAPEC-87
CAPEC-107
CAPEC-111
CAPEC-127
CAPEC-141
CAPEC-142
CAPEC-148
CAPEC-218
CAPEC-237
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
CAPEC-477
CAPEC-480
CAPEC-665
CAPEC-668
CAPEC-701
Affected products
Firefox < 140.1.0Firefox < 141.0Thunderbird < 140.1.0Thunderbird < 141.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.002 · p12
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-57 · CWE-693
└ via CAPEC-127 · CWE-693
└ via CAPEC-665 · CWE-345
└ via CAPEC-148 · CWE-345
└ via CAPEC-665 · CWE-345
└ via CAPEC-665 · CWE-345
└ via CAPEC-141 · CWE-345
└ via CAPEC-668 · CWE-693
└ via CAPEC-142 · CWE-345
└ via CAPEC-480 · CWE-693
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
Tracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
mozjs102Tracked
mozjs102Tracked
mozjs115Tracked
mozjs115Tracked
mozjs78Tracked
mozjs91Tracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
firefox*Tracked
Showing first 20 of 21
Source databases
ANC
AST
DEB
CVE
UBU
Related vulnerabilities