INFSA-2025:21842: thunderbird security update
Information about definition
Identificator: INFSA-2025:21842
Type: security
Release date: 2025-12-07 23:05:05 UTC
Information about package
Mozilla Thunderbird is a standalone mail and newsgroup client.
Vulnerabilities description
- CVE-2025-13012
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a race condition in the Graphics component. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
- CVE-2025-13013
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by a mitigation bypass in the DOM: Core & HTML component. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to bypass security restrictions.
- CVE-2025-13014
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the Audio/Video component. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
- CVE-2025-13015
Mozilla Firefox could allow a remote attacker to conduct spoofing attacks. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to conduct a spoofing attack.
- CVE-2025-13016
Mozilla Firefox is vulnerable to a buffer overflow, caused by an incorrect boundary conditions in the JavaScript: WebAssembly component. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
- CVE-2025-13017
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by a same-origin policy bypass in the DOM: Notifications component. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to bypass security restrictions.
- CVE-2025-13018
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by a mitigation bypass in the DOM: Security component. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to bypass security restrictions.
- CVE-2025-13019
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by a same-origin policy bypass in the DOM: Workers component. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to bypass security restrictions.
- CVE-2025-13020
Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the WebRTC: Audio/Video component. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
Severity level
| CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
|---|---|---|---|
|
NIST — CVE-2025-13012
|
no information | 7.5 | no information |
|
NIST — CVE-2025-13013
|
no information | 6.1 | no information |
|
NIST — CVE-2025-13014
|
no information | 6.1 | no information |
|
NIST — CVE-2025-13015
|
no information | 3.4 | no information |
|
NIST — CVE-2025-13016
|
no information | 7.5 | no information |
|
NIST — CVE-2025-13017
|
no information | 6.1 | no information |
|
NIST — CVE-2025-13018
|
no information | 6.1 | no information |
|
NIST — CVE-2025-13019
|
no information | 6.1 | no information |
|
NIST — CVE-2025-13020
|
no information | 6.1 | no information |
Updated packages