cbcvebase.
CVE-2017-7829
published 2018-06-11

CVE-2017-7829: It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed…

PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.80%
76.1th percentile
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.

Affected

24 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianthunderbird< thunderbird 1:52.5.2-1 (bookworm)thunderbird 1:52.5.2-1 (bookworm)
mozillathunderbird< 52.5.252.5.2
mozillathunderbird>= 0 < 1:52.5.2-11:52.5.2-1
mozillathunderbird>= 0 < 1:52.5.2-11:52.5.2-1
mozillathunderbird>= 0 < 1:52.5.2-11:52.5.2-1
mozillathunderbird>= 0 < 1:52.5.2-11:52.5.2-1
mozillathunderbird>= 0 < 1:52.6.0+build1-0ubuntu0.14.04.11:52.6.0+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:52.6.0+build1-0ubuntu0.16.04.11:52.6.0+build1-0ubuntu0.16.04.1
mozillathunderbird>= unspecified < 52.5.252.5.2
redhatenterprise_linux_aus
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.