Логотип exploitDog
bind:"CVE-2021-23993" OR bind:"CVE-2021-23992" OR bind:"CVE-2021-23991"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-23993" OR bind:"CVE-2021-23992" OR bind:"CVE-2021-23991"

Количество 22

Количество 22

oracle-oval логотип

ELSA-2021-1193

почти 5 лет назад

ELSA-2021-1193: thunderbird security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-1192

почти 5 лет назад

ELSA-2021-1192: thunderbird security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0580-1

почти 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
ubuntu логотип

CVE-2021-23993

больше 4 лет назад

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-23993

почти 5 лет назад

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23993

больше 4 лет назад

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23993

больше 4 лет назад

An attacker may perform a DoS attack to prevent a user from sending en ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1167-1

почти 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
github логотип

GHSA-3pj2-rvj5-6646

больше 3 лет назад

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2021-02076

около 5 лет назад

Уязвимость почтового клиента Thunderbird, связанная с недостаточной проверкой импортированных ключей OpenPGP, позволяющая нарушителю отправлять произвольные зашифрованные сообщения

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-23992

больше 4 лет назад

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-23992

почти 5 лет назад

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-23992

больше 4 лет назад

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-23992

больше 4 лет назад

Thunderbird did not check if the user ID associated with an OpenPGP ke ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-23991

больше 4 лет назад

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2021-23991

почти 5 лет назад

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-23991

больше 4 лет назад

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2021-23991

больше 4 лет назад

If a Thunderbird user has previously imported Alice's OpenPGP key, and ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-x89c-f42w-ch2g

больше 3 лет назад

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

EPSS: Низкий
github логотип

GHSA-x5j6-p8w8-5r65

больше 3 лет назад

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2021-1193

ELSA-2021-1193: thunderbird security update (MODERATE)

почти 5 лет назад
oracle-oval логотип
ELSA-2021-1192

ELSA-2021-1192: thunderbird security update (MODERATE)

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0580-1

Security update for MozillaThunderbird

почти 5 лет назад
ubuntu логотип
CVE-2021-23993

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-23993

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-23993

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-23993

An attacker may perform a DoS attack to prevent a user from sending en ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1167-1

Security update for MozillaThunderbird

почти 5 лет назад
github логотип
GHSA-3pj2-rvj5-6646

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-02076

Уязвимость почтового клиента Thunderbird, связанная с недостаточной проверкой импортированных ключей OpenPGP, позволяющая нарушителю отправлять произвольные зашифрованные сообщения

CVSS3: 5.4
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-23992

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-23992

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-23992

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-23992

Thunderbird did not check if the user ID associated with an OpenPGP ke ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-23991

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-23991

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.8
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-23991

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-23991

If a Thunderbird user has previously imported Alice's OpenPGP key, and ...

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-x89c-f42w-ch2g

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x5j6-p8w8-5r65

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу