CVE-2025-2830
published 2025-04-15CVE-2025-2830: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when…
PriorityP431medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.34%
25.8th percentile
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:128.10.0esr-1~deb12u1 (bookworm) | thunderbird 1:128.10.0esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 128.9.2 | 128.9.2 |
| mozilla | thunderbird | >= 0 < 1:128.10.1esr-1~deb11u1 | 1:128.10.1esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1~deb12u1 | 1:128.10.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1 | 1:128.10.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1 | 1:128.10.0esr-1 |
| mozilla | thunderbird | >= 129.0 < 137.0.2 | 137.0.2 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g6gh-87cw-x396: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /t
ghsa_unreviewed·2025-04-15
CVE-2025-2830 [MEDIUM] CWE-22 GHSA-g6gh-87cw-x396: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /t
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
OSV
CVE-2025-2830: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /t
osv·2025-04-15·CVSS 6.3
CVE-2025-2830 [MEDIUM] CVE-2025-2830: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /t
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2025-07-22
CVE-2025-4083 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart thunderbird to
make all the necessary changes.
Red Hat
thunderbird: Information Disclosure of /tmp directory listing
vendor_redhat·2025-04-15·CVSS 6.3
CVE-2025-2830 [MEDIUM] CWE-200 thunderbird: Information Disclosure of /tmp directory listing
thunderbird: Information Disclosure of /tmp directory listing
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listi
Debian
CVE-2025-2830: thunderbird - By crafting a malformed file name for an attachment in a multipart message, an a...
vendor_debian·2025·CVSS 6.3
CVE-2025-2830 [MEDIUM] CVE-2025-2830: thunderbird - By crafting a malformed file name for an attachment in a multipart message, an a...
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Scope: local
bookworm: resolved (fixed in 1:128.10.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.10.1esr-1~deb11u1)
forky: resolved (fixed in 1:128.10.0esr-1)
sid: resolved (fixed in 1:128.10.0esr-1)
trixie: resolved (fixed in 1:128.10.0esr-1)
Mozilla
Mozilla Foundation Security Advisory 2025-26: CVE-2025-2830
vendor_mozilla·CVSS 6.3
CVE-2025-2830 [MEDIUM] Mozilla Foundation Security Advisory 2025-26: CVE-2025-2830
Mozilla Foundation Security Advisory 2025-26
CVE: CVE-2025-2830
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 137.0.2
Mozilla
Mozilla Foundation Security Advisory 2025-27: CVE-2025-2830
vendor_mozilla·CVSS 6.3
CVE-2025-2830 [MEDIUM] Mozilla Foundation Security Advisory 2025-27: CVE-2025-2830
Mozilla Foundation Security Advisory 2025-27
CVE: CVE-2025-2830
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 128.9.2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-15
Published