CVE-2006-4570Thunderbird vulnerability

11 documents7 sources
Severity
2.6LOWNVD
EPSS
2.1%
top 15.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateMay 3

Description

Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages4 packages

Debianmozilla/thunderbird< 1.5.0.7-1+3
NVDmozilla/thunderbird1.5.0.6
debiandebian/thunderbird< thunderbird 1.5.0.7-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-23g7-p8vx-g5m2: Mozilla Thunderbird before 12022-05-03
OSV
CVE-2006-4570: Mozilla Thunderbird before 12006-09-15

📋Vendor Advisories

5
Ubuntu
Mozilla vulnerabilities2006-10-10
Ubuntu
Thunderbird vulnerabilities2006-09-25
Ubuntu
Thunderbird vulnerabilities2006-09-22
Red Hat
security flaw2006-09-15
Debian
CVE-2006-4570: thunderbird - Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images...2006

💬Community

3
Bugzilla
CVE-2006-4570 security flaw2018-08-16
Bugzilla
CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)2006-09-14
Bugzilla
CVE-2006-4340 Various Thunderbird security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4570 CVE-2006-4571)2006-09-14