Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-3032

Опубликовано: 22 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

РелизСтатусПримечание
bionic

released

1:102.2.2+build1-0ubuntu0.18.04.1
devel

not-affected

1:102.3.3+build1-0ubuntu1
esm-infra/focal

DNE

focal

released

1:102.2.2+build1-0ubuntu0.20.04.1
jammy

released

1:102.2.2+build1-0ubuntu0.22.04.1
kinetic

ignored

end of life, was needs-triage
lunar

not-affected

1:102.3.3+build1-0ubuntu1
trusty

ignored

end of standard support
upstream

released

91.13.1
xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 46%
0.00232
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
почти 3 года назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.5
nvd
больше 2 лет назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.5
debian
больше 2 лет назад

When receiving an HTML email that contained an <code>iframe</code> ele ...

CVSS3: 6.5
github
больше 2 лет назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 9.8
fstec
почти 3 года назад

Уязвимость почтового клиента Thunderbird, связанная с ошибками при обработке входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 46%
0.00232
Низкий

6.5 Medium

CVSS3