Количество 5
Количество 5
CVE-2026-84637
(Malicious calendar invitations could use file URI attachments to launc ...)
CVE-2026-84637
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
CVE-2026-84637
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
CVE-2026-84637
Malicious calendar invitations could use file URI attachments to launc ...
GHSA-3q74-4f83-x4rj
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-84637 (Malicious calendar invitations could use file URI attachments to launc ...) | CVSS3: 9.8 | 0% Низкий | 15 дней назад | |
CVE-2026-84637 Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. | CVSS3: 8.8 | 0% Низкий | 15 дней назад | |
CVE-2026-84637 Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. | CVSS3: 9.8 | 0% Низкий | 15 дней назад | |
CVE-2026-84637 Malicious calendar invitations could use file URI attachments to launc ... | CVSS3: 9.8 | 0% Низкий | 15 дней назад | |
GHSA-3q74-4f83-x4rj Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. | CVSS3: 9.8 | 0% Низкий | 15 дней назад |
Уязвимостей на страницу