Логотип exploitDog
bind:"GHSA-p4jr-wm76-h2v3" OR bind:"CVE-2022-4055"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-p4jr-wm76-h2v3" OR bind:"CVE-2022-4055"

Количество 9

Количество 9

github логотип

GHSA-p4jr-wm76-h2v3

больше 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2022-4055

больше 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-4055

больше 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2022-4055

больше 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2022-4055

около 1 года назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2022-4055

больше 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improp ...

CVSS3: 7.4
EPSS: Низкий
rocky логотип

RLSA-2025:7672

6 месяцев назад

Moderate: xdg-utils security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7672

11 месяцев назад

ELSA-2025-7672: xdg-utils security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-04910

больше 3 лет назад

Уязвимость утилиты для открытия почтового клиента из набора xdg-utils xdg-mail, связанная с недостаточной проверкой введенных пользователем данных, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p4jr-wm76-h2v3

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improp ...

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2025:7672

Moderate: xdg-utils security update

0%
Низкий
6 месяцев назад
oracle-oval логотип
ELSA-2025-7672

ELSA-2025-7672: xdg-utils security update (MODERATE)

11 месяцев назад
fstec логотип
BDU:2025-04910

Уязвимость утилиты для открытия почтового клиента из набора xdg-utils xdg-mail, связанная с недостаточной проверкой введенных пользователем данных, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу