Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18350
HistoryMay 02, 2019 - 6:37 a.m.

Access Controls Bypass

2019-05-0206:37:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.003

Percentile

66.3%

Mozilla Thunderbird is vulnerable to access controls bypass. File downloads encoded with blob: and data: URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. Malicious sites could lure users into downloading executables that would otherwise be detected as suspicious.