CVE-2025-4086

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

09 May 2025, 19:33

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1945705 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1945705 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-28/ - () https://www.mozilla.org/security/advisories/mfsa2025-28/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-31/ - () https://www.mozilla.org/security/advisories/mfsa2025-31/ - Vendor Advisory
First Time Mozilla
Mozilla thunderbird
Mozilla firefox
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

01 May 2025, 15:16

Type Values Removed Values Added
Summary
  • (es) Un nombre de archivo especialmente manipulado que contiene una gran cantidad de caracteres de nueva línea codificados podría ocultar la extensión del archivo al mostrarse en el cuadro de diálogo de descarga. *Este error solo afecta a Firefox para Android. Las demás versiones de Firefox no se ven afectadas.* Esta vulnerabilidad afecta a Firefox (versión anterior a la 138) y Thunderbird (versión anterior a la 138).
Summary (en) A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138. (en) A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.

29 Apr 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-451

29 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 14:15

Updated : 2025-05-09 19:33


NVD link : CVE-2025-4086

Mitre link : CVE-2025-4086

CVE.ORG link : CVE-2025-4086


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information