Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23023
HistoryApr 10, 2020 - 12:12 a.m.

Arbitrary Code Execution

2020-04-1000:12:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.967

Percentile

99.6%

thunderbird is vulnerable to arbtirary code execution. Several flaws were found in the way Thunderbird processed certain malformed JavaScript code. A malicious HTML mail message could execute JavaScript code in such a way that may result in Thunderbird crashing or executing arbitrary code as the user running Thunderbird. JavaScript support is disabled by default in Thunderbird; these issues are not exploitable unless the user has enabled JavaScript.

References