VDB
CVE-2006-0884
CVE-2006-0884
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
EPSS 7.23% · 94.0th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
7.23%
94.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mozilla | thunderbird | 1.0.6, 0, 0.1 |
| n/a | n/a | n/a |
Timeline
- Feb 24, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- RHSA-2006:0330 vendor-advisory
- 19941 third-party-advisory
- 19821 third-party-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm url
- SSRT061158 vendor-advisory
- HPSBUX02156 vendor-advisory
- 16770 vdb
- FLSA:189137-1 vendor-advisory
- 19950 third-party-advisory
- mozilla-inline-fwd-code-execution(25983) vdb
- oval:org.mitre.oval:def:2024 vdb
- 20060404-01-U vendor-advisory
- DSA-1051 vendor-advisory
- GLSA-200604-18 vendor-advisory
- oval:org.mitre.oval:def:10782 vdb
- http://www.mozilla.org/security/announce/2006/mfsa2006-21.html url
- MDKSA-2006:076 vendor-advisory
- DSA-1046 vendor-advisory
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt technical
- http://secunia.com/advisories/19721 advisory
…and 23 more