INFCSA-2025:18321: thunderbird security update

Information about definition

Identificator: INFCSA-2025:18321

Type: security

Release date: 2025-11-11 15:26:29 UTC

Information about package

Mozilla Thunderbird is a standalone mail and newsgroup client.

Vulnerabilities description

  • CVE-2025-11708

    Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in MediaTrackGraphImpl::GetInstance(). By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.

  • CVE-2025-11709

    Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds read/write in a privileged process triggered by WebGL textures. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.

  • CVE-2025-11710

    Mozilla Firefox could allow a remote attacker to obtain sensitive information, caused by the leaking of cross-process information due to malicious IPC messages. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to obtain sensitive information.

  • CVE-2025-11711

    Mozilla Firefox could allow a remote attacker to bypass security restrictions. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to modify some non-writable Object properties.

  • CVE-2025-11712

    A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header.

  • CVE-2025-11714

    Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.

  • CVE-2025-11715

    Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 7.5 no information
no information 7.5 no information
no information 7.5 no information
no information 7.5 no information
no information 6.1 no information
no information 7.5 no information
no information 7.5 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download