
[CIVN-2025-0323] Multiple Vulnerabilities in Mozilla Thunderbird
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Mozilla Thunderbird
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Mozilla Thunderbird versions prior to 145
Mozilla Thunderbird versions prior to 140.5
Overview
Multiple vulnerabilities have been reported in Mozilla Thunderbird which could allow an attacker to execute arbitrary code on the targeted system.
Target Audience:
All end-user organizations and individuals using Mozilla Thunderbird.
Risk Assessment:
High risk of system compromise and service disruptions.
Impact Assessment:
Potential for system compromise and service unavailability.
Description
These vulnerabilities exist in Mozilla Thunderbird due to Race condition in the Graphics compo-nent, Same-origin policy bypass in the DOM, Mitigation bypass in the DOM, Use-after-free in the WebRTC, Audio/Video component; Spoofing issue in Thunderbird, Incorrect boundary conditions in the Graphics, JavaScript; Race condition in the Graphics component, Sandbox escape due to incorrect boundary conditions in the Graphics, JIT miscompilation in the JavaScript Engine and Memory safety bugs. A remote attacker could exploit these vulnerabilities by convincing the victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-90/
https://www.mozilla.org/en-US/security/advisories/mfsa2025-91/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2025-90/
https://www.mozilla.org/en-US/security/advisories/mfsa2025-91/
CVE Name
CVE-2025-13012
CVE-2025-13013
CVE-2025-13014
CVE-2025-13015
CVE-2025-13016
CVE-2025-13017
CVE-2025-13018
CVE-2025-13019
CVE-2025-13020
CVE-2025-13021
CVE-2025-13022
CVE-2025-13023
CVE-2025-13024
CVE-2025-13025
CVE-2025-13026
CVE-2025-13027
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmkcifoACgkQ3jCgcSdc
ys8aQg//WUddb8hdwlNVVj/UTSXnyE72MmTgF/aCgiUXDpv/l9Nqsy7TT6vbpZ9f
YR16mjG1hwORSJ5Mar+5cKKNyhOilB2G7/7hH7Co1LchiIh26Z6pwdkeHnnSZZlg
5+dzvC3wKMscguZ3lZoxGb89ecP9YUE86PWTWI1Sfun2Vpype/4hybVb20FwrF8l
KhJgHoUeqpgJK+Ol/RU/55QorR4bYQboyGtiEVmmQHwHvydc/IiiWvnQ//QIzGTq
MQXbW05x5ZANp1vEvJct8tE/c6yPwUB+CpLZm0En7Dh1BG0JsF4cHQoz0aYu4xu5
LEDo5EbclFEG5pTYUpkGvbnUYgnPM6g+AkQWSgGhtUuYknIbWRYnh9hB2fC61J+a
aW2A1Yz4MkrgJrDIU+pIJQFMi3gkoJx0RogbQUUeyMi9uSfhypuwYruBvKj3on5j
P6RPkr3EZIChAhSOBafGOrG6lM+yy1ATKpaBM/Qcy61Z85KiDxtw6psWUj3kReFx
LjZR57VtBCxPQSSil5PJGnxlRCqSlITaF3iifocPtXlsOd1xO0diLG5uY+DhJaGX
B1nu98150BxZOTUEd8gyk9svbPiVAVIBUKvf7vY41Bo88SfySnG5sKJ56h0dB88I
behaPAx44icQZKRJ3GrPxwDIQk4xccLgOqb/Su9BKLIaC5b45rw=
=kfS+
—–END PGP SIGNATURE—–


