CVE-2025-4087 | A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbird 128.10.
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbird 128.10.
- 🔗 bugzilla.mozilla.org/show_bug.cgi
- 🔗 www.mozilla.org/security/advisories/mfsa2025-28/
- 🔗 www.mozilla.org/security/advisories/mfsa2025-29/
- 🔗 www.mozilla.org/security/advisories/mfsa2025-31/
- 🔗 www.mozilla.org/security/advisories/mfsa2025-32/
- 🔗 lists.debian.org/debian-lts-announce/2025/05/msg00024.html
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-17 | 2026-09-30 |
|---|---|---|
| ≥90 % | 0 | 392 |
| ≥50 % | 0 | 1149 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 424 |
CVE-2025-4087 | A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbird 128.10.
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vul
Noch keine Analyse zu CVE-2025-4087
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.