8.1
CVE-2025-9180
- EPSS 0.06%
- Veröffentlicht 19.08.2025 20:33:54
- Zuletzt bearbeitet 13.04.2026 15:17:13
- Quelle security@mozilla.org
- CVE-Watchlists
- Unerledigt
Same-origin policy bypass in the Graphics: Canvas2D component
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird SwEditionesr Version < 128.14.0
Mozilla ≫ Thunderbird SwEdition- Version < 142.0
Mozilla ≫ Thunderbird SwEditionesr Version >= 140.0 < 140.2.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.175 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.