CVE-2025-0510
published 2025-02-04CVE-2025-0510: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This…
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.23%
14.3th percentile
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:128.7.0esr-1~deb12u1 (bookworm) | thunderbird 1:128.7.0esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:128.7.0esr-1~deb11u1 | 1:128.7.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.7.0esr-1~deb12u1 | 1:128.7.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.7.0esr-1 | 1:128.7.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.7.0esr-1 | 1:128.7.0esr-1 |
| mozilla | thunderbird | >= 128.0.1 < 128.7.0 | 128.7.0 |
| mozilla | thunderbird | >= 131.0 < 135.0 | 135.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9h64-69xj-vx28: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040
ghsa_unreviewed·2025-02-04·CVSS 7.5
CVE-2025-0510 [HIGH] CWE-345 GHSA-9h64-69xj-vx28: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
OSV
CVE-2025-0510: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040
osv·2025-02-04·CVSS 7.5
CVE-2025-0510 [HIGH] CVE-2025-0510: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2025-07-22
CVE-2025-4083 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart thunderbird to
make all the necessary changes.
Red Hat
thunderbird: Address of e-mail sender can be spoofed by malicious email
vendor_redhat·2025-02-04·CVSS 7.5
CVE-2025-0510 [HIGH] CWE-451 thunderbird: Address of e-mail sender can be spoofed by malicious email
thunderbird: Address of e-mail sender can be spoofed by malicious email
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: thunderbird (Red Hat Enterprise Linux 10) - Not affected
Package: thunderbird-flatpak-container (Red Hat E
Debian
CVE-2025-0510: thunderbird - Thunderbird displayed an incorrect sender address if the From field of an email ...
vendor_debian·2025·CVSS 7.5
CVE-2025-0510 [HIGH] CVE-2025-0510: thunderbird - Thunderbird displayed an incorrect sender address if the From field of an email ...
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
Scope: local
bookworm: resolved (fixed in 1:128.7.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.7.0esr-1~deb11u1)
forky: resolved (fixed in 1:128.7.0esr-1)
sid: resolved (fixed in 1:128.7.0esr-1)
trixie: resolved (fixed in 1:128.7.0esr-1)
Mozilla
Mozilla Foundation Security Advisory 2025-10: CVE-2025-0510
vendor_mozilla·CVSS 6.5
CVE-2025-0510 [MEDIUM] Mozilla Foundation Security Advisory 2025-10: CVE-2025-0510
Mozilla Foundation Security Advisory 2025-10
CVE: CVE-2025-0510
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 128.7
Mozilla
Mozilla Foundation Security Advisory 2025-11: CVE-2025-0510
vendor_mozilla·CVSS 6.5
CVE-2025-0510 [MEDIUM] Mozilla Foundation Security Advisory 2025-11: CVE-2025-0510
Mozilla Foundation Security Advisory 2025-11
CVE: CVE-2025-0510
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 135
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-04
Published