Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-68214
HistoryMar 06, 2023 - 12:00 a.m.

Mozilla Thunderbird and Firefox Arbitrary Code Execution Vulnerability

2023-03-0600:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
mozilla
thunderbird
firefox
vulnerability
code execution
imap
pop
html
exploited

0.001 Low

EPSS

Percentile

50.6%

Mozilla Thunderbird is the United States Mozilla Foundation’s set of independent from the Mozilla Application Suite e-mail client software. The program supports IMAP, POP mail protocols and HTML mail format. An arbitrary code execution vulnerability exists in Mozilla Thunderbird versions prior to 91.6, Firefox versions prior to 97, and Firefox ESR versions prior to 91.6. The vulnerability can be exploited to cause a user to drag and drop an image to their desktop or folder to run arbitrary code.