CVE-2005-0148Mozilla Thunderbird vulnerability

2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/thunderbird0.6, 0.7, 0.8+2

🔴Vulnerability Details

1
GHSA
GHSA-6wgp-m8wf-9325: Thunderbird before 02022-05-01