6.5
CVE-2025-14331
- EPSS 0.18%
- Veröffentlicht 09.12.2025 13:38:07
- Zuletzt bearbeitet 07.10.2026 20:10:01
- Erkennungen
Same-origin policy bypass in the Request Handling component
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird SwEdition esr Version < 140.6.0
Mozilla ≫ Thunderbird SwEdition - Version < 146.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.08 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| CISA-ADP | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://www.mozilla.org/security/advisories/mfsa2025-92/
https://www.mozilla.org/security/advisories/mfsa2025-94/
https://www.mozilla.org/security/advisories/mfsa2025-93/
https://bugzilla.mozilla.org/show_bug.cgi?id=2000218
https://www.mozilla.org/security/advisories/mfsa2025-95/
https://www.mozilla.org/security/advisories/mfsa2025-96/