Lucene search

K
cveRedhatCVE-2006-4570
HistorySep 15, 2006 - 7:07 p.m.

CVE-2006-4570

2006-09-1519:07:00
redhat
web.nvd.nist.gov
53
"cve-2006-4570
mozilla thunderbird
seamonkey
remote user-assisted
javascript bypass"

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.053

Percentile

93.1%

Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with “Load Images” enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.

Affected configurations

Nvd
Node
mozillaseamonkeyRange1.0.4
OR
mozillathunderbirdRange1.5.0.6
VendorProductVersionCPE
mozillathunderbirdcpe:/a:mozilla:thunderbird::::
mozillaseamonkeycpe:/a:mozilla:seamonkey::::

References

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.053

Percentile

93.1%