Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23137
HistoryApr 10, 2020 - 12:17 a.m.

Cross-Site Scripting (XSS)

2020-04-1000:17:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.491

Percentile

97.5%

thunderbird is vulnerable to cross-site scripting. Several flaws were found in the way Thunderbird processed certain malformed JavaScript code. A malicious HTML email message containing JavaScript code could cause Thunderbird to crash or potentially execute arbitrary code as the user running Thunderbird. JavaScript support is disabled by default in Thunderbird; these issues are not exploitable unless the user has enabled JavaScript.

References