Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  Debian DLA | DLA-4231-1 | firefox-esr security update | 
|  Debian DLA | DLA-4239-1 | thunderbird security update | 
|  Debian DSA | DSA-5950-1 | firefox-esr security update | 
|  Debian DSA | DSA-5959-1 | thunderbird security update | 
|  EUVD | EUVD-2025-19101 | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | 
|  Ubuntu USN | USN-7663-1 | Thunderbird vulnerabilities | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID | The WebCompat WebExtension shipped with Firefox exposed a persistent UUID | 
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 04 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID | firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID | 
Thu, 03 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Mozilla Mozilla firefox | |
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | |
| Vendors & Products | Mozilla Mozilla firefox | 
Wed, 02 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12. | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | 
| References |  | 
Wed, 02 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat rhel Aus Redhat rhel E4s Redhat rhel Els Redhat rhel Eus Redhat rhel Tus | |
| CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/a:redhat:rhel_aus:8.2 cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_aus:8.6 cpe:/a:redhat:rhel_e4s:8.6 cpe:/a:redhat:rhel_e4s:8.8 cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_e4s:9.2 cpe:/a:redhat:rhel_eus:9.4 cpe:/a:redhat:rhel_tus:8.6 cpe:/a:redhat:rhel_tus:8.8 cpe:/o:redhat:enterprise_linux:10.0 cpe:/o:redhat:rhel_els:7 | |
| Vendors & Products | Redhat rhel Aus Redhat rhel E4s Redhat rhel Els Redhat rhel Eus Redhat rhel Tus | 
Wed, 02 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat Redhat enterprise Linux | |
| CPEs | cpe:/a:redhat:enterprise_linux:8 | |
| Vendors & Products | Redhat Redhat enterprise Linux | 
Thu, 26 Jun 2025 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Wed, 25 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics | cvssV3_1 
 | ssvc 
 
 | 
Wed, 25 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID | |
| References |  | |
| Metrics | threat_severity 
 | cvssV3_1 
 
 | 
Tue, 24 Jun 2025 12:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-10-30T15:59:25.655Z
Reserved: 2025-06-20T14:51:28.050Z
Link: CVE-2025-6425
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-06-25T14:21:44.307Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-06-24T13:15:23.403
Modified: 2025-07-03T16:23:06.293
Link: CVE-2025-6425
 Redhat
                        Redhat
                     OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-07-06T22:16:28Z