目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-4084— Mozilla Firefox ESR 安全漏洞

AI Predicted 7.8 Difficulty: Easy EPSS 0.40% · P33
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-4084の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Potential local code execution in "copy as cURL" command
ソース: CVE Program / CVE List V5
脆弱性説明
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox ESR 128.10, Firefox ESR 115.23, and Thunderbird 128.10.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Mozilla Firefox ESR 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Mozilla Firefox ESR是美国Mozilla基金会的Firefox(Web浏览器)的一个延长支持版本。 Mozilla Firefox ESR 128.10之前版本和115.23之前版本存在安全漏洞,该漏洞源于copy as cURL功能对特殊字符转义不足,可能导致本地代码执行。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
MozillaFirefox 115.23 ~ 115.* -
MozillaThunderbird 128.10 ~ * -

II. CVE-2025-4084の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-4084のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-4084 厂商安全公告 (4)

Same Patch Batch · Mozilla · 2025-04-29 · 13 CVEs total

CVE-2025-4093Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10
CVE-2025-4092Memory safety bugs fixed in Firefox 138 and Thunderbird 138
CVE-2025-4091Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderb
CVE-2025-4090Leaked library paths in Thunderbird for Android
CVE-2025-4089Potential local code execution in "copy as cURL" command
CVE-2025-4088Cross-site request forgery via storage access API redirects
CVE-2025-4087Unsafe attribute access during XPath parsing
CVE-2025-4086Specially crafted filename could be used to obscure download type
CVE-2025-4085Potential information leakage and privilege escalation in UITour actor
CVE-2025-4083Process isolation bypass using "javascript:" URI links in cross-origin frames
CVE-2025-4082WebGL shader attribute memory corruption in Thunderbird for macOS
CVE-2025-2817Privilege escalation in Thunderbird Updater

IV. 関連脆弱性

V. CVE-2025-4084へのコメント

まだコメントはありません


コメントを残す