Mondoo Vulnerability Intelligence
Search vulnerabilities and malicious packages across npm, PyPI, Go, GitHub Actions, VS Code, and more.
Search vulnerabilities and malicious packages across npm, PyPI, Go, GitHub Actions, VS Code, and more.
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
firefox: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146 (CVE-2025-14333)
firefox: Use-after-free in the WebRTC: Signaling component (CVE-2025-14321)
firefox: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2025-14325)
firefox: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2025-14322)
firefox: Privilege escalation in the Netmonitor component (CVE-2025-14328)
firefox: Privilege escalation in the Netmonitor component (CVE-2025-14329)
firefox: Same-origin policy bypass in the Request Handling component (CVE-2025-14331)
firefox: Privilege escalation in the DOM: Notifications component (CVE-2025-14323)
firefox: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2025-14330)
firefox: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2025-14324)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:140.6.0-1.el9_7Exploitability
AV:NAC:HPR:NUI:RScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H