Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3385

Опубликовано: 27 окт. 2009
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=530159SeaMonkey scriptable plugin execution in mail (mfsa2010-06)

EPSS

Процентиль: 80%
0.01388
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

nvd
почти 16 лет назад

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

debian
почти 16 лет назад

The mail component in Mozilla SeaMonkey before 1.1.19 does not properl ...

github
почти 4 года назад

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

EPSS

Процентиль: 80%
0.01388
Низкий

5.8 Medium

CVSS2