The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Feb 11, 2025 | Feb 4, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Feb 26, 2025 | Feb 4, 2025 |
| Debian | — | Upgrade thunderbird | Feb 10, 2025 | Feb 4, 2025 |
| Freebsd | — | Upgrade mozilla | Feb 8, 2025 | Feb 7, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 135.0Upgrade to the latest version of Mozilla Thunderbird | Feb 5, 2025 | Feb 4, 2025 |
| Oracle_linux | — | Upgrade thunderbird | Feb 10, 2025 | Feb 4, 2025 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoNo solution existsUpgrade thunderbirdUpgrade thunderbird-debugsource | Feb 11, 2025 | Feb 4, 2025 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Feb 14, 2025 | Feb 4, 2025 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-common | Feb 12, 2025 | Feb 4, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 23, 2025 | Feb 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub