{"cve": "CVE-2025-11712", "updated": null, "url": null, "affected": [{"ecosystem": "Debian:11", "package": "firefox-esr", "affected": null, "fixed": "140.4.0esr-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:12", "package": "firefox-esr", "affected": null, "fixed": "140.4.0esr-1~deb12u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:13", "package": "firefox-esr", "affected": null, "fixed": "140.4.0esr-1~deb13u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:14", "package": "firefox-esr", "affected": null, "fixed": "140.4.0esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:11", "package": "firefox-esr", "affected": null, "fixed": "140.4.0esr-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DLA-4335-1"}, {"ecosystem": "Debian:11", "package": "thunderbird", "affected": null, "fixed": "1:140.4.0esr-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:12", "package": "thunderbird", "affected": null, "fixed": "1:140.4.0esr-1~deb12u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:13", "package": "thunderbird", "affected": null, "fixed": "1:140.4.0esr-1~deb13u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:14", "package": "thunderbird", "affected": null, "fixed": "1:140.4.0esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2025-11712"}, {"ecosystem": "Debian:11", "package": "thunderbird", "affected": null, "fixed": "1:140.4.0esr-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DLA-4351-1"}, {"ecosystem": "Ubuntu:22.04:LTS", "package": "thunderbird", "affected": null, "fixed": "1:140.7.1+build1-0ubuntu0.22.04.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2025-11712"}, {"ecosystem": "SUSE:Linux Enterprise Server 16.0", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:21021-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP applications 16.0", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:21021-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Desktop Applications 15 SP6", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Desktop Applications 15 SP7", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP3-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP3", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Enterprise Storage 7.1", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "openSUSE:Leap 15.6", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-150200.152.207.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3775-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP5-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-112.286.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3808-1"}, {"ecosystem": "SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "140.4.0-112.286.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:3808-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Desktop Applications 15 SP6", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Desktop Applications 15 SP7", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP3-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP3", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Enterprise Storage 7.1", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "openSUSE:Leap 15.6", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-150200.152.210.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4173-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP5-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-112.289.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4174-1"}, {"ecosystem": "SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-112.289.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4174-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Package Hub 15 SP6", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-150200.8.242.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4006-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Package Hub 15 SP7", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-150200.8.242.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4006-1"}, {"ecosystem": "SUSE:Linux Enterprise Workstation Extension 15 SP6", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-150200.8.242.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4006-1"}, {"ecosystem": "SUSE:Linux Enterprise Workstation Extension 15 SP7", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-150200.8.242.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4006-1"}, {"ecosystem": "openSUSE:Leap 15.6", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-150200.8.242.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2025:4006-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaFirefox", "affected": null, "fixed": "144.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2025:15645-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "MozillaFirefox", "affected": null, "fixed": "140.5.0-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2025:20065-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2025:15646-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "MozillaThunderbird", "affected": null, "fixed": "140.4.0-bp160.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2025:20026-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "firefox-esr", "affected": null, "fixed": "140.4.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2025:15632-1"}, {"ecosystem": "Red Hat:enterprise_linux:10.0", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:18154"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:18155"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:18285"}, {"ecosystem": "Red Hat:rhel_els:7", "package": "firefox", "affected": null, "fixed": "0:140.4.0-4.el7_9", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19278"}, {"ecosystem": "Red Hat:rhel_aus:8.2::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21054"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21055"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21055"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21056"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21056"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21056"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21057"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21057"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el9_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21058"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21059"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "firefox", "affected": null, "fixed": "0:140.4.0-3.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:21064"}, {"ecosystem": "Red Hat:enterprise_linux:10.0", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:18320"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:18321"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:18983"}, {"ecosystem": "Red Hat:rhel_aus:8.2::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19938"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19939"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19939"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19941"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19941"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19941"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19942"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19942"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el9_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19943"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19944"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.4.0-2.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2025:19945"}]}