Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xmh-3jxc-r2w6

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

EPSS

Процентиль: 56%
0.00333
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-610
CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.1
redhat
около 3 лет назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.5
nvd
почти 3 года назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.5
debian
почти 3 года назад

When receiving an HTML email that contained an <code>iframe</code> ele ...

CVSS3: 9.8
fstec
около 3 лет назад

Уязвимость почтового клиента Thunderbird, связанная с ошибками при обработке входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 56%
0.00333
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-610
CWE-863