CVE-2022-3032
published 2022-12-22CVE-2022-3032: When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.66%
47.6th percentile
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:102.2.1-1 (bookworm) | thunderbird 1:102.2.1-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 91.13.1 | 91.13.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.18.04.1 | 1:102.2.2+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.20.04.1 | 1:102.2.2+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.22.04.1 | 1:102.2.2+build1-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= 102.0 < 102.2.1 | 102.2.1 |
| mozilla | thunderbird | >= unspecified < 102.2.1 | 102.2.1 |
| mozilla | thunderbird | >= unspecified < 91.13.1 | 91.13.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2022-10-07·CVSS 8.8
CVE-2022-36059 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
spoof the mouse pointer position, obtain sensitive information, spoof the
contents of the addressbar, bypass security restrictions, or execute
arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319,
CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477,
CVE-2022-38478)
Multiple security issues were discovered in Thunderbird. An attacker could
potentially exploit these in order to determine when a user opens a
specially crafted message. (CVE-2022-3032, CVE-2022-303
Red Hat
Mozilla: Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked
vendor_redhat·2022-08-31·CVSS 6.5
CVE-2022-3032 [MEDIUM] CWE-1021 Mozilla: Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked
Mozilla: Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of when receiving an HTML email that contained an `iframe` element, which used a `srcdoc` attribute to define the internal HTML document, remote objects specified in the nested document (for example, images or vi
Debian
CVE-2022-3032: thunderbird - When receiving an HTML email that contained an <code>iframe</code> element, whic...
vendor_debian·2022·CVSS 6.5
CVE-2022-3032 [MEDIUM] CVE-2022-3032: thunderbird - When receiving an HTML email that contained an <code>iframe</code> element, whic...
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Scope: local
bookworm: resolved (fixed in 1:102.2.1-1)
bullseye: resolved
forky: resolved (fixed in 1:102.2.1-1)
sid: resolved (fixed in 1:102.2.1-1)
trixie: resolved (fixed in 1:102.2.1-1)
Mozilla
Mozilla Foundation Security Advisory 2022-39: CVE-2022-3032
vendor_mozilla·CVSS 6.5
CVE-2022-3032 [MEDIUM] Mozilla Foundation Security Advisory 2022-39: CVE-2022-3032
Mozilla Foundation Security Advisory 2022-39
CVE: CVE-2022-3032
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 91.13.1
Mozilla
Mozilla Foundation Security Advisory 2022-38: CVE-2022-3032
vendor_mozilla·CVSS 6.5
CVE-2022-3032 [MEDIUM] Mozilla Foundation Security Advisory 2022-38: CVE-2022-3032
Mozilla Foundation Security Advisory 2022-38
CVE: CVE-2022-3032
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 102.2.1
GHSA
GHSA-2xmh-3jxc-r2w6: When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specifi
ghsa_unreviewed·2022-12-22
CVE-2022-3032 [MEDIUM] CWE-610 GHSA-2xmh-3jxc-r2w6: When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specifi
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
OSV
CVE-2022-3032: When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specifi
osv·2022-12-22·CVSS 6.5
CVE-2022-3032 [MEDIUM] CVE-2022-3032: When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specifi
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
OSV
thunderbird vulnerabilities
osv·2022-10-07·CVSS 8.8
CVE-2022-2505 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
spoof the mouse pointer position, obtain sensitive information, spoof the
contents of the addressbar, bypass security restrictions, or execute
arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319,
CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477,
CVE-2022-38478)
Multiple security issues were discovered in Thunderbird. An attacker could
potentially exploit these in order to determine when a user opens a
specially crafted message. (CVE-2022-3032, CVE-2022-3034)
It was discovered that Thunderbird did not correctly handle HTML
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1783831https://www.mozilla.org/security/advisories/mfsa2022-38/https://www.mozilla.org/security/advisories/mfsa2022-39/https://bugzilla.mozilla.org/show_bug.cgi?id=1783831https://www.mozilla.org/security/advisories/mfsa2022-38/https://www.mozilla.org/security/advisories/mfsa2022-39/
2022-12-22
Published