Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-90099
HistoryAug 25, 2021 - 12:00 a.m.

Mozilla Thunderbird Command Injection Vulnerability

2021-08-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.002 Low

EPSS

Percentile

52.8%

Mozilla Thunderbird is an open source email client. A command injection vulnerability exists in the Mozilla Thunderbird product, which stems from a problem in the way Thunderbird handles IMAP server responses sent prior to the STARTTLS process. An attacker could exploit this vulnerability to send arbitrary IMAP commands before the STARTTLS handshake and execute them after the handshake completes.

CPENameOperatorVersion
mozilla thunderbirdlt78.12