Lucene search

K
nvd[email protected]NVD:CVE-2006-0884
HistoryFeb 24, 2006 - 10:02 p.m.

CVE-2006-0884

2006-02-2422:02:00
CWE-20
web.nvd.nist.gov
5

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

Low

EPSS

0.95

Percentile

99.3%

The WYSIWYG rendering engine (“rich mail” editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.

Affected configurations

Nvd
Node
mozillathunderbirdRange1.0.7
OR
mozillathunderbirdMatch0.1
OR
mozillathunderbirdMatch0.2
OR
mozillathunderbirdMatch0.3
OR
mozillathunderbirdMatch0.4
OR
mozillathunderbirdMatch0.5
OR
mozillathunderbirdMatch0.6
OR
mozillathunderbirdMatch0.7
OR
mozillathunderbirdMatch0.7.1
OR
mozillathunderbirdMatch0.7.2
OR
mozillathunderbirdMatch0.7.3
OR
mozillathunderbirdMatch0.8
OR
mozillathunderbirdMatch0.9
OR
mozillathunderbirdMatch1.0
OR
mozillathunderbirdMatch1.0.1
OR
mozillathunderbirdMatch1.0.2
OR
mozillathunderbirdMatch1.0.5
OR
mozillathunderbirdMatch1.0.6
VendorProductVersionCPE
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozillathunderbird0.1cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:*
mozillathunderbird0.2cpe:2.3:a:mozilla:thunderbird:0.2:*:*:*:*:*:*:*
mozillathunderbird0.3cpe:2.3:a:mozilla:thunderbird:0.3:*:*:*:*:*:*:*
mozillathunderbird0.4cpe:2.3:a:mozilla:thunderbird:0.4:*:*:*:*:*:*:*
mozillathunderbird0.5cpe:2.3:a:mozilla:thunderbird:0.5:*:*:*:*:*:*:*
mozillathunderbird0.6cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*
mozillathunderbird0.7cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*
mozillathunderbird0.7.1cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*
mozillathunderbird0.7.2cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

Low

EPSS

0.95

Percentile

99.3%