CVE-2017-7846
published 2018-06-11CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard…
PriorityP340high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.01%
78.6th percentile
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | thunderbird | < thunderbird 1:52.5.2-1 (bookworm) | thunderbird 1:52.5.2-1 (bookworm) |
| mozilla | thunderbird | < 52.5.2 | 52.5.2 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.5.2-1 | 1:52.5.2-1 |
| mozilla | thunderbird | >= 0 < 1:52.6.0+build1-0ubuntu0.14.04.1 | 1:52.6.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.6.0+build1-0ubuntu0.16.04.1 | 1:52.6.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52.5.2 | 52.5.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2529-rwp4-75f6: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e
ghsa_unreviewed·2022-05-14
CVE-2017-7846 [HIGH] CWE-74 GHSA-2529-rwp4-75f6: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
OSV
CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e
osv·2018-06-11·CVSS 8.8
CVE-2017-7846 [HIGH] CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
OSV
thunderbird vulnerabilities
osv·2018-01-29·CVSS 5.3
CVE-2017-7829 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that a From address encoded with a null character is
cut off in the message header display. An attacker could potentially
exploit this to spoof the sender address. (CVE-2017-7829)
It was discovered that it is possible to execute JavaScript in RSS feeds
in some circumstances. If a user were tricked in to opening a specially
crafted RSS feed, an attacker could potentially exploit this in
combination with another vulnerability, in order to cause unspecified
problems. (CVE-2017-7846)
It was discovered that the RSS feed can leak local path names. If a user
were tricked in to opening a specially crafted RSS feed, an attacker
could potentially exploit this to obtain sensitive information.
(CVE-2017-7847)
It was discovered that RSS feeds are vulner
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-01-29·CVSS 5.3
CVE-2017-7829 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that a From address encoded with a null character is
cut off in the message header display. An attacker could potentially
exploit this to spoof the sender address. (CVE-2017-7829)
It was discovered that it is possible to execute JavaScript in RSS feeds
in some circumstances. If a user were tricked in to opening a specially
crafted RSS feed, an attacker could potentially exploit this in
combination with another vulnerability, in order to cause unspecified
problems. (CVE-2017-7846)
It was discovered that the RSS feed can leak local path names. If a user
were tricked in to opening a specially crafted RSS feed, an attacker
could potentially exploit this to obtain sensitive infor
Red Hat
Mozilla: JavaScript Execution via RSS in mailbox:// origin
vendor_redhat·2017-12-22·CVSS 8.8
CVE-2017-7846 [HIGH] Mozilla: JavaScript Execution via RSS in mailbox:// origin
Mozilla: JavaScript Execution via RSS in mailbox:// origin
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
Debian
CVE-2017-7846: thunderbird - It is possible to execute JavaScript in the parsed RSS feed when RSS feed is vie...
vendor_debian·2017·CVSS 8.8
CVE-2017-7846 [HIGH] CVE-2017-7846: thunderbird - It is possible to execute JavaScript in the parsed RSS feed when RSS feed is vie...
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
Scope: local
bookworm: resolved (fixed in 1:52.5.2-1)
bullseye: resolved (fixed in 1:52.5.2-1)
forky: resolved (fixed in 1:52.5.2-1)
sid: resolved (fixed in 1:52.5.2-1)
trixie: resolved (fixed in 1:52.5.2-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102258http://www.securitytracker.com/id/1040123https://access.redhat.com/errata/RHSA-2018:0061https://bugzilla.mozilla.org/show_bug.cgi?id=1411716https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlhttps://www.debian.org/security/2017/dsa-4075https://www.mozilla.org/security/advisories/mfsa2017-30/http://www.securityfocus.com/bid/102258http://www.securitytracker.com/id/1040123https://access.redhat.com/errata/RHSA-2018:0061https://bugzilla.mozilla.org/show_bug.cgi?id=1411716https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlhttps://www.debian.org/security/2017/dsa-4075https://www.mozilla.org/security/advisories/mfsa2017-30/
2018-06-11
Published