vulnerability
Oracle Linux: CVE-2023-37208: ELSA-2023-4062: thunderbird security update (IMPORTANT) (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:M/Au:N/C:C/I:C/A:C) | Jul 4, 2023 | Jul 18, 2023 | Dec 3, 2025 |
Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Jul 4, 2023
Added
Jul 18, 2023
Modified
Dec 3, 2025
Description
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
The Mozilla Foundation Security Advisory describes this flaw as:
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code.
The Mozilla Foundation Security Advisory describes this flaw as:
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code.
Solutions
oracle-linux-upgrade-firefoxoracle-linux-upgrade-firefox-x11oracle-linux-upgrade-thunderbird
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.