Project Subscriptions
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4231-1 | firefox-esr security update |
Debian DLA |
DLA-4239-1 | thunderbird security update |
Debian DSA |
DSA-5950-1 | firefox-esr security update |
Debian DSA |
DSA-5959-1 | thunderbird security update |
EUVD |
EUVD-2025-21378 | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. |
Ubuntu USN |
USN-7663-1 | Thunderbird vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12. |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 30 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com | Incorrect parsing of URLs could have allowed embedding of youtube.com |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12. | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. |
| References |
|
Fri, 04 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com | firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com |
Thu, 03 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* |
|
| Vendors & Products |
Mozilla
Mozilla firefox |
Wed, 02 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Els Redhat rhel Eus Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/a:redhat:rhel_aus:8.2 cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_aus:8.6 cpe:/a:redhat:rhel_e4s:8.6 cpe:/a:redhat:rhel_e4s:8.8 cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_e4s:9.2 cpe:/a:redhat:rhel_eus:9.4 cpe:/a:redhat:rhel_tus:8.6 cpe:/a:redhat:rhel_tus:8.8 cpe:/o:redhat:enterprise_linux:10.0 cpe:/o:redhat:rhel_els:7 |
|
| Vendors & Products |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Els Redhat rhel Eus Redhat rhel Tus |
Wed, 02 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:enterprise_linux:8 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Thu, 26 Jun 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-706 | |
| References |
|
Wed, 25 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 | |
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 25 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 24 Jun 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:30:42.931Z
Reserved: 2025-06-20T14:51:34.184Z
Link: CVE-2025-6429
Updated: 2025-11-03T20:07:03.248Z
Status : Modified
Published: 2025-06-24T13:15:23.877
Modified: 2026-04-13T15:17:07.070
Link: CVE-2025-6429
OpenCVE Enrichment
Updated: 2025-07-06T22:16:30Z
Debian DLA
Debian DSA
EUVD
Ubuntu USN