Lucene search

K
mozillaMozilla FoundationMFSA2006-26
HistoryApr 13, 2006 - 12:00 a.m.

Mail Multiple Information Disclosure — Mozilla

2006-04-1300:00:00
Mozilla Foundation
www.mozilla.org
22

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.03

Percentile

90.9%

As a privacy measure to prevent senders (primarily spammers) from tracking when e-mail is read Thunderbird does not load remote content referenced from an HTML mail message until a user tells it to do so. This normally includes the content of frames and CSS files, but CrashFr showed it was possible to bypass this restriction through indirection: the direct CSS or iframe src is included in-line, with that including remote content.

Affected configurations

Vulners
Node
mozillathunderbirdRange<1.0.8
OR
mozillathunderbirdRange<1.5.0.2
VendorProductVersionCPE
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.03

Percentile

90.9%