Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21375 | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140. |
Ubuntu USN |
USN-7991-1 | Thunderbird vulnerabilities |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140. | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140 and Thunderbird 140. |
Thu, 30 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: HTTPS-Only exception screen lacked anti-clickjacking delay | HTTPS-Only exception screen lacked anti-clickjacking delay |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140. | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140. |
| References |
|
Thu, 03 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Mozilla
Mozilla firefox |
Thu, 26 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: HTTPS-Only exception screen lacked anti-clickjacking delay | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 25 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1021 | |
| Metrics |
cvssV3_1
|
Tue, 24 Jun 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:31:11.320Z
Reserved: 2025-06-20T14:51:40.757Z
Link: CVE-2025-6434
Updated: 2025-06-25T14:20:24.853Z
Status : Modified
Published: 2025-06-24T13:15:24.447
Modified: 2026-04-13T15:17:07.977
Link: CVE-2025-6434
OpenCVE Enrichment
Updated: 2026-04-20T17:00:12Z
EUVD
Ubuntu USN