CVE-2025-0510
Last modified
CVE-2025-0510 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Thunderbird | >= 128.0.1, < 128.7.0 |
| Mozilla | Thunderbird | >= 131.0, < 135.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1940570Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-11/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-0510?
How severe is CVE-2025-0510?
How do I fix CVE-2025-0510?
Are you affected by CVE-2025-0510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
