CVE-2025-3523
published 2025-04-15CVE-2025-3523: When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering…
PriorityP431medium6.4CVSS 3.1
AVNACHPRNUIRSUCLIHAL
EPSS
0.30%
22.0th percentile
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:128.10.0esr-1~deb12u1 (bookworm) | thunderbird 1:128.10.0esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 128.9.2 | 128.9.2 |
| mozilla | thunderbird | >= 0 < 1:128.10.1esr-1~deb11u1 | 1:128.10.1esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1~deb12u1 | 1:128.10.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1 | 1:128.10.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1 | 1:128.10.0esr-1 |
| mozilla | thunderbird | >= 129.0 < 137.0.2 | 137.0.2 |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
osv6.4MEDIUM
vendor_debian6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-3523: When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hov
osv·2025-04-15·CVSS 6.4
CVE-2025-3523 [MEDIUM] CVE-2025-3523: When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hov
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
GHSA
GHSA-4h7q-pj8m-5675: When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hov
ghsa_unreviewed·2025-04-15
CVE-2025-3523 [MEDIUM] CWE-451 GHSA-4h7q-pj8m-5675: When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hov
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2025-07-22
CVE-2025-4083 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart thunderbird to
make all the necessary changes.
Debian
CVE-2025-3523: thunderbird - When an email contains multiple attachments with external links via the X-Mozill...
vendor_debian·2025·CVSS 6.4
CVE-2025-3523 [MEDIUM] CVE-2025-3523: thunderbird - When an email contains multiple attachments with external links via the X-Mozill...
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Scope: local
bookworm: resolved (fixed in 1:128.10.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.10.1esr-1~deb11u1)
forky: resolved (fixed in 1:128.10.0esr-1)
sid: resolved (fixed in 1:128.10.0esr-1)
trixie: resolved (fixed in 1:128.10.0esr-1)
Mozilla
Mozilla Foundation Security Advisory 2025-26: CVE-2025-3523
vendor_mozilla·CVSS 6.4
CVE-2025-3523 [MEDIUM] Mozilla Foundation Security Advisory 2025-26: CVE-2025-3523
Mozilla Foundation Security Advisory 2025-26
CVE: CVE-2025-3523
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 137.0.2
Mozilla
Mozilla Foundation Security Advisory 2025-27: CVE-2025-3523
vendor_mozilla·CVSS 6.4
CVE-2025-3523 [MEDIUM] Mozilla Foundation Security Advisory 2025-27: CVE-2025-3523
Mozilla Foundation Security Advisory 2025-27
CVE: CVE-2025-3523
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 128.9.2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-15
Published