Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xmh-3jxc-r2w6

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

EPSS

Процентиль: 46%
0.00232
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-610
CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.1
redhat
почти 3 года назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.5
nvd
больше 2 лет назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.5
debian
больше 2 лет назад

When receiving an HTML email that contained an <code>iframe</code> ele ...

CVSS3: 9.8
fstec
почти 3 года назад

Уязвимость почтового клиента Thunderbird, связанная с ошибками при обработке входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 46%
0.00232
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-610
CWE-863