Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4109-1 | firefox-esr security update |
Debian DLA |
DLA-4110-1 | thunderbird security update |
Debian DSA |
DSA-5889-1 | firefox-esr security update |
Debian DSA |
DSA-5891-1 | thunderbird security update |
EUVD |
EUVD-2025-9300 | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. |
Ubuntu USN |
USN-7663-1 | Thunderbird vulnerabilities |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9. |
| Title | firefox: thunderbird: URL Bar Spoofing via non-BMP Unicode characters | URL Bar Spoofing via non-BMP Unicode characters |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 14 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10.0 |
Mon, 07 Apr 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Els
|
|
| CPEs | cpe:/a:redhat:rhel_aus:8.2 cpe:/a:redhat:rhel_aus:8.6 cpe:/a:redhat:rhel_e4s:8.6 cpe:/a:redhat:rhel_eus:8.8 cpe:/a:redhat:rhel_tus:8.6 cpe:/o:redhat:rhel_els:7 |
|
| Vendors & Products |
Redhat rhel Els
|
Mon, 07 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox Mozilla thunderbird |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mozilla
Mozilla firefox Mozilla thunderbird |
Fri, 04 Apr 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat rhel Aus Redhat rhel E4s Redhat rhel Eus Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9 cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_e4s:8.4 cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_eus:9.2 cpe:/a:redhat:rhel_eus:9.4 cpe:/a:redhat:rhel_tus:8.4 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat rhel Aus Redhat rhel E4s Redhat rhel Eus Redhat rhel Tus |
Wed, 02 Apr 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9. | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. |
Wed, 02 Apr 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: thunderbird: URL Bar Spoofing via non-BMP Unicode characters | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:26:00.288Z
Reserved: 2025-03-31T09:35:20.446Z
Link: CVE-2025-3029
Updated: 2025-11-03T19:46:49.584Z
Status : Modified
Published: 2025-04-01T13:15:41.290
Modified: 2026-04-13T15:16:56.460
Link: CVE-2025-3029
OpenCVE Enrichment
Updated: 2026-04-22T02:00:05Z
Debian DLA
Debian DSA
EUVD
Ubuntu USN