CVE-2025-4087

Public on 2025-04-29
Modified on 2025-05-02
Description
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2 - Firefox Extra firefox 2025-05-21 ALAS2FIREFOX-2025-038 Fixed
HAQM Linux 2023 firefox 2025-05-21 ALAS2023-2025-976 Fixed
HAQM Linux 2 - Core thunderbird 2025-05-21 ALAS2-2025-2858 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
NVD CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N