Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: Mitigation bypass in the DOM: Security component (CVE-2025-13018) * firefox: Use-after-free in the Audio/Video component (CVE-2025-13014) * firefox: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2025-13016) * firefox: Same-origin policy bypass in the DOM: Workers component (CVE-2025-13019) * firefox: Use-after-free in the WebRTC: Audio/Video component (CVE-2025-13020) * firefox: Race condition in the Graphics component (CVE-2025-13012) * firefox: Spoofing issue in Firefox (CVE-2025-13015) * firefox: Mitigation bypass in the DOM: Core & HTML component (CVE-2025-13013) * firefox: Same-origin policy bypass in the DOM: Notifications component (CVE-2025-13017) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: Mitigation bypass in the DOM: Security component (CVE-2025-13018) * firefox: Use-after-free in the Audio/Video component (CVE-2025-13014) * firefox: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2025-13016) * firefox: Same-origin policy bypass in the DOM: Workers component (CVE-2025-13019) * firefox: Use-after-free in the WebRTC: Audio/Video component (CVE-2025-13020) * firefox: Race condition in the Graphics component (CVE-2025-13012) * firefox: Spoofing issue in Firefox (CVE-2025-13015) * firefox: Mitigation bypass in the DOM: Core & HTML component (CVE-2025-13013) * firefox: Same-origin policy bypass in the DOM: Notifications component (CVE-2025-13017) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:21881
- https://access.redhat.com/security/cve/CVE-2025-13012
- https://access.redhat.com/security/cve/CVE-2025-13013
- https://access.redhat.com/security/cve/CVE-2025-13014
- https://access.redhat.com/security/cve/CVE-2025-13015
- https://access.redhat.com/security/cve/CVE-2025-13016
- https://access.redhat.com/security/cve/CVE-2025-13017
- https://access.redhat.com/security/cve/CVE-2025-13018
- https://access.redhat.com/security/cve/CVE-2025-13019
- https://access.redhat.com/security/cve/CVE-2025-13020
- https://bugzilla.redhat.com/2414079
- https://bugzilla.redhat.com/2414080
- https://bugzilla.redhat.com/2414083
- https://bugzilla.redhat.com/2414084
- https://bugzilla.redhat.com/2414085
- https://bugzilla.redhat.com/2414086
- https://bugzilla.redhat.com/2414090
- https://bugzilla.redhat.com/2414091
- https://bugzilla.redhat.com/2414092
- https://errata.almalinux.org/8/ALSA-2025-21881.html