cbcvebase.
CVE-2025-13015
published 2025-11-11

CVE-2025-13015: Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.

low3.4CVSS 3.1
AVNACHPRNUIRSCCLINAN
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 145.0-1 (sid)firefox 145.0-1 (sid)
debianfirefox-esr< firefox 145.0-1 (sid)firefox 145.0-1 (sid)
debianthunderbird< firefox 145.0-1 (sid)firefox 145.0-1 (sid)
mozillafirefox< 115.30.0115.30.0
mozillafirefox< 145.0145.0
mozillafirefox
mozillafirefox>= 140.0 < 140.5.0140.5.0
mozillathunderbird>= 0 < 1:140.5.0esr-1~deb11u11:140.5.0esr-1~deb11u1
mozillathunderbird>= 0 < 1:140.5.0esr-1~deb12u11:140.5.0esr-1~deb12u1
mozillathunderbird>= 0 < 1:140.5.0esr-1~deb13u11:140.5.0esr-1~deb13u1
mozillathunderbird>= 0 < 1:140.5.0esr-11:140.5.0esr-1

CVSS provenance

nvdv3.13.4LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
osv3.4LOW