The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Feb 24, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-bin. | Oct 30, 2017 | Feb 24, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.1 | Nov 21, 2013 | Feb 24, 2006 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.0.8Upgrade to Mozilla Thunderbird version 1.5.0.2 | Nov 21, 2013 | Feb 24, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub