Vulnerability Details CVE-2025-0510
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.4%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2025-0510
-
cpe:2.3:a:mozilla:thunderbird:*
-
cpe:2.3:a:mozilla:thunderbird:128.0.1
-
cpe:2.3:a:mozilla:thunderbird:128.1.0
-
cpe:2.3:a:mozilla:thunderbird:128.1.1
-
cpe:2.3:a:mozilla:thunderbird:128.2.0
-
cpe:2.3:a:mozilla:thunderbird:128.2.1
-
cpe:2.3:a:mozilla:thunderbird:128.2.2
-
cpe:2.3:a:mozilla:thunderbird:128.2.3
-
cpe:2.3:a:mozilla:thunderbird:128.3.0
-
cpe:2.3:a:mozilla:thunderbird:128.3.1
-
cpe:2.3:a:mozilla:thunderbird:128.3.2
-
cpe:2.3:a:mozilla:thunderbird:128.3.3
-
cpe:2.3:a:mozilla:thunderbird:128.4.0
-
cpe:2.3:a:mozilla:thunderbird:128.4.1
-
cpe:2.3:a:mozilla:thunderbird:128.4.2
-
cpe:2.3:a:mozilla:thunderbird:128.4.3
-
cpe:2.3:a:mozilla:thunderbird:128.4.4
-
cpe:2.3:a:mozilla:thunderbird:128.5.0
-
cpe:2.3:a:mozilla:thunderbird:128.5.1
-
cpe:2.3:a:mozilla:thunderbird:128.5.2
-
cpe:2.3:a:mozilla:thunderbird:128.6.0