INFSA-2025:10073: firefox security update
Information about definition
Identificator: INFSA-2025:10073
Type: security
Release date: 2025-07-17 21:49:17 UTC
Information about package
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Vulnerabilities description
- CVE-2025-6424
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: A use-after-free in FontFaceSet resulted in a potentially exploitable crash.
- CVE-2025-6425
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser and persisted between containers and normal/private browsing mode but not profiles.
- CVE-2025-6429
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an embed tag. This could have bypassed website security checks that restricted which domains users were allowed to embed.
- CVE-2025-6430
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: When a file download is specified via the Content-Disposition header, that directive would be ignored if the file was included via a or tag, potentially making a website vulnerable to a cross-site scripting attack.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2025-6424
|
no information | 7.5 | no information |
NIST — CVE-2025-6425
|
no information | 6.1 | no information |
NIST — CVE-2025-6429
|
no information | 6.1 | no information |
NIST — CVE-2025-6430
|
no information | 6.1 | no information |
Updated packages