Логотип exploitDog
bind:CVE-2022-4055
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4055

Количество 8

Количество 8

ubuntu логотип

CVE-2022-4055

больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-4055

почти 3 года назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2022-4055

больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2022-4055

4 месяца назад

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2022-4055

больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improp ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-p4jr-wm76-h2v3

больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
EPSS: Низкий
oracle-oval логотип

ELSA-2025-7672

30 дней назад

ELSA-2025-7672: xdg-utils security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-04910

почти 3 года назад

Уязвимость утилиты для открытия почтового клиента из набора xdg-utils xdg-mail, связанная с недостаточной проверкой введенных пользователем данных, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improp ...

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-p4jr-wm76-h2v3

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2025-7672

ELSA-2025-7672: xdg-utils security update (MODERATE)

30 дней назад
fstec логотип
BDU:2025-04910

Уязвимость утилиты для открытия почтового клиента из набора xdg-utils xdg-mail, связанная с недостаточной проверкой введенных пользователем данных, позволяющая нарушителю оказать влияние на целостность защищаемой информации

CVSS3: 7.4
0%
Низкий
почти 3 года назад

Уязвимостей на страницу