{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-14T23:55:44.376","vulnerabilities":[{"cve":{"id":"CVE-2025-3523","sourceIdentifier":"security@mozilla.org","published":"2025-04-15T15:16:09.957","lastModified":"2026-04-13T15:16:57.847","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2."},{"lang":"es","value":"Cuando un correo electrónico contiene varios archivos adjuntos con enlaces externos mediante el encabezado X-Mozilla-External-Attachment-URL, solo se muestra el último enlace al pasar el cursor sobre cualquier archivo adjunto. Aunque se usa el enlace correcto al hacer clic, el texto engañoso al pasar el cursor podría inducir a los usuarios a descargar contenido de fuentes no confiables. Esta vulnerabilidad afecta a Thunderbird (versión anterior a la 137.0.2) y Thunderbird (versión anterior a la 128.9.2)."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:L\/I:H\/A:L","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":4.7}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-451"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndExcluding":"128.9.2","matchCriteriaId":"D11A3908-71D7-4967-8029-0D4DD57F384C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionStartIncluding":"129.0","versionEndExcluding":"137.0.2","matchCriteriaId":"971D9339-D135-4B63-A4DA-E333080DA5E6"}]}]}],"references":[{"url":"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1958385","source":"security@mozilla.org","tags":["Permissions Required"]},{"url":"https:\/\/www.mozilla.org\/security\/advisories\/mfsa2025-26\/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https:\/\/www.mozilla.org\/security\/advisories\/mfsa2025-27\/","source":"security@mozilla.org","tags":["Vendor Advisory"]}]}}]}