Multiple Vulnerabilities in Mozilla Thunderbird Could Allow for Arbitrary Code Execution
ID: a80179f9-a49d-5f47-8ada-95ee580da07c
STIX ID: report--a80179f9-a49d-5f47-8ada-95ee580da07c
Feed Name: CISecurity.org Advisories
Multiple security vulnerabilities were disclosed in Mozilla Thunderbird (with related Firefox fixes), the most severe being a use-after-free in FontFaceSet that could enable arbitrary code execution (CVE-2025-6424) and other memory-safety fixes (CVE-2025-6436). The advisory lists several additional lower-severity issues (e.g., CSP bypass, DNS leaks, WebAuthn, Content-Disposition handling) and notes that successful exploitation could allow attackers to install programs or access and modify user data depending on account privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
