logo

Multiple Vulnerabilities in Mozilla Thunderbird Could Allow for Arbitrary Code Execution

ID: a80179f9-a49d-5f47-8ada-95ee580da07c

STIX ID: report--a80179f9-a49d-5f47-8ada-95ee580da07c

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-07-09

Date Updated: 2026-04-27

...
...

Multiple security vulnerabilities were disclosed in Mozilla Thunderbird (with related Firefox fixes), the most severe being a use-after-free in FontFaceSet that could enable arbitrary code execution (CVE-2025-6424) and other memory-safety fixes (CVE-2025-6436). The advisory lists several additional lower-severity issues (e.g., CSP bypass, DNS leaks, WebAuthn, Content-Disposition handling) and notes that successful exploitation could allow attackers to install programs or access and modify user data depending on account privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.