CVE Vulnerabilities

CVE-2025-0510

Published: Feb 04, 2025 | Modified: Apr 13, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.

Affected Software

NameVendorStart VersionEnd Version
ThunderbirdMozilla128.0.1 (including)128.7.0 (excluding)
ThunderbirdMozilla131.0 (including)135.0 (excluding)
Red Hat Enterprise Linux 8RedHatthunderbird-0:128.7.0-1.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatthunderbird-0:128.7.0-1.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatthunderbird-0:128.7.0-1.el8_4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatthunderbird-0:128.7.0-1.el8_4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatthunderbird-0:128.7.0-1.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatthunderbird-0:128.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatthunderbird-0:128.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatthunderbird-0:128.7.0-1.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatthunderbird-0:128.7.0-1.el8_8*
Red Hat Enterprise Linux 9RedHatthunderbird-0:128.7.0-1.el9_5*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatthunderbird-0:128.7.0-1.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatthunderbird-0:128.7.0-1.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatthunderbird-0:128.7.0-1.el9_4*
ThunderbirdUbuntufocal*
ThunderbirdUbuntujammy*
ThunderbirdUbuntuupstream*

References