CVE-2025-6430 | When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
- 🔗 bugzilla.mozilla.org/show_bug.cgi
- 🔗 www.mozilla.org/security/advisories/mfsa2025-51/
- 🔗 www.mozilla.org/security/advisories/mfsa2025-53/
- 🔗 www.mozilla.org/security/advisories/mfsa2025-54/
- 🔗 www.mozilla.org/security/advisories/mfsa2025-55/
- 🔗 lists.debian.org/debian-lts-announce/2025/06/msg00029.html
- 🔗 lists.debian.org/debian-lts-announce/2025/07/msg00002.html
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-18 | 2026-10-01 |
|---|---|---|
| ≥90 % | 0 | 377 |
| ≥50 % | 0 | 1137 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 451 |
CVE-2025-6430 | When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scriptin
Noch keine Analyse zu CVE-2025-6430
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.