#VU103615 Input validation error in Mozilla Thunderbird - CVE-2025-1015
Published: February 4, 2025 / Updated: February 7, 2025
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when handling the Address Book URI fields. A remote attacker create and export an address book containing a malicious payload in a field, trick the victim into clicking on the link after importing the address book and a web page inside Thunderbird.