CVE-2018-5184 — Inadequate Encryption Strength in Mozilla Thunderbird
CWE-326 — Inadequate Encryption StrengthCWE-200 — Sensitive Information Exposure8 documents8 sources
Severity
7.5HIGHNVD
EPSS
1.0%
top 22.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages8 packages
Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04, Enterprise Linux 6.0, 7.0, 7.6, 7.5
🔴Vulnerability Details
3GHSA▶
GHSA-p5x3-568x-9fq9: Using remote content in encrypted messages can lead to the disclosure of plaintext↗2022-05-14
OSV▶
CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext↗2018-06-11
CVEList▶
CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext↗2018-06-11
📋Vendor Advisories
3💬Community
1Bugzilla
▶