A vulnerability marked as critical has been reported in Mozilla Thunderbird up to 137.x. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2025-4091. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Mozilla Thunderbird up to 137.x on Android and classified as problematic. Affected by this issue is some unknown functionality of the component Logcat. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-4090. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability marked as problematic has been reported in Mozilla Thunderbird up to 137.x. Affected by this issue is some unknown functionality of the component Copy as cURL Handler. The manipulation leads to command injection.
This vulnerability is handled as CVE-2025-4089. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 137.x on Android. Affected by this vulnerability is an unknown functionality of the component Logcat. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-4090. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in Mozilla Firefox up to 137.x. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2025-4091. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in Mozilla Firefox up to 137.x. Affected by this vulnerability is an unknown functionality of the component Copy as cURL Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2025-4089. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Mozilla Firefox up to 137.x. This issue affects some unknown processing of the component Storage Access API. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-4088. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird up to 137.x. Affected is an unknown function of the component Storage Access API. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-4088. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Thunderbird up to 137.x. It has been classified as critical. This vulnerability affects unknown code of the component XPath Parser. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2025-4087. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Mozilla Firefox up to 137 on Android. This affects an unknown part of the component Filename Handler. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is uniquely identified as CVE-2025-4086. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Mozilla Thunderbird up to 137 on Android. This vulnerability affects unknown code of the component Filename Handler. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability was named CVE-2025-4086. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Firefox up to 137.x and classified as critical. This affects an unknown part of the component XPath Parser. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-4087. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Firefox up to 137.x. It has been declared as critical. This affects an unknown part of the component UITour. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2025-4085. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Thunderbird up to 137.x. It has been rated as critical. This vulnerability affects unknown code of the component UITour. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2025-4085. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Mozilla Firefox ESR up to 115.22/128.9 on Windows. This issue affects some unknown processing of the component Copy as cURL Handler. The manipulation leads to escaping of output.
The identification of this vulnerability is CVE-2025-4084. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability identified as problematic has been detected in Mozilla Thunderbird ESR up to 115.22/128.9 on Windows. Affected is an unknown function of the component Copy as cURL Handler. The manipulation leads to escaping of output.
This vulnerability is traded as CVE-2025-4084. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Apple QuickTime and Darwin Streaming Server up to 4.1.3e. Affected is an unknown function of the file view_broadcast.cgi. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2003-0422. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.