CVE-2025-0510

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135. (en) Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.

06 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-345

06 Feb 2025, 19:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1940570 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1940570 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-10/ - () https://www.mozilla.org/security/advisories/mfsa2025-10/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-11/ - () https://www.mozilla.org/security/advisories/mfsa2025-11/ - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Mozilla
Mozilla thunderbird
Summary
  • (es) Thunderbird mostraba una dirección de remitente incorrecta si el campo De de un correo electrónico utilizaba la sintaxis de nombre de grupo no válida que se describe en CVE-2024-49040. Esta vulnerabilidad afecta a Thunderbird &lt; 128.7 y Thunderbird &lt; 135.
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

04 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-04 14:15

Updated : 2026-04-13 15:16


NVD link : CVE-2025-0510

Mitre link : CVE-2025-0510

CVE.ORG link : CVE-2025-0510


JSON object : View

Products Affected

mozilla

  • thunderbird
CWE
NVD-CWE-noinfo CWE-345

Insufficient Verification of Data Authenticity