vulnerability

Oracle Linux: CVE-2023-37208: ELSA-2023-4062: thunderbird security update (IMPORTANT) (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Jul 4, 2023
Added
Jul 18, 2023
Modified
Dec 3, 2025

Description

When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
The Mozilla Foundation Security Advisory describes this flaw as:
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code.

Solutions

oracle-linux-upgrade-firefoxoracle-linux-upgrade-firefox-x11oracle-linux-upgrade-thunderbird
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.