suse · CVE-2025-4083

Quick triage

Priority: high Published: 2025-04-29 23:16:25 UTC Updated: 2026-04-16 14:37:06 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2025-4083 severity important: SUSE including 23 source package names (MozillaFirefox-128.10.0-150200.152.179.1, MozillaFirefox-138.0-1.1, …), 105 product×package rows across 38 product lines (Container suse/kiosk/firefox-esr, Image SLES15-SP3-SAP-Azure-LI-BYOS-Production, … (38 product lines)): Fixed 105.

Description:

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.

cvelogic Threat Intelligence