CVE-2022-3034
published 2022-12-22CVE-2022-3034: When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.53%
41.6th percentile
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:102.2.1-1 (bookworm) | thunderbird 1:102.2.1-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 91.31.1 | 91.31.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.1-1 | 1:102.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.18.04.1 | 1:102.2.2+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.20.04.1 | 1:102.2.2+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.2.2+build1-0ubuntu0.22.04.1 | 1:102.2.2+build1-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= 102.0 < 102.2.1 | 102.2.1 |
| mozilla | thunderbird | >= unspecified < 102.2.1 | 102.2.1 |
| mozilla | thunderbird | >= unspecified < 91.13.1 | 91.13.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2022-10-07·CVSS 8.8
CVE-2022-36059 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
spoof the mouse pointer position, obtain sensitive information, spoof the
contents of the addressbar, bypass security restrictions, or execute
arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319,
CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477,
CVE-2022-38478)
Multiple security issues were discovered in Thunderbird. An attacker could
potentially exploit these in order to determine when a user opens a
specially crafted message. (CVE-2022-3032, CVE-2022-303
Red Hat
Mozilla: An iframe element in an HTML email could trigger a network request
vendor_redhat·2022-08-31·CVSS 4.3
CVE-2022-3034 [MEDIUM] CWE-449 Mozilla: An iframe element in an HTML email could trigger a network request
Mozilla: An iframe element in an HTML email could trigger a network request
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of sending a request to the remote document when receiving an HTML email that specified to load an `iframe` element from a remote location. However, Thunderbird didn't display the document.
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2022-3034: thunderbird - When receiving an HTML email that specified to load an <code>iframe</code> eleme...
vendor_debian·2022·CVSS 4.3
CVE-2022-3034 [MEDIUM] CVE-2022-3034: thunderbird - When receiving an HTML email that specified to load an <code>iframe</code> eleme...
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Scope: local
bookworm: resolved (fixed in 1:102.2.1-1)
bullseye: resolved
forky: resolved (fixed in 1:102.2.1-1)
sid: resolved (fixed in 1:102.2.1-1)
trixie: resolved (fixed in 1:102.2.1-1)
Mozilla
Mozilla Foundation Security Advisory 2022-38: CVE-2022-3034
vendor_mozilla·CVSS 4.3
CVE-2022-3034 [MEDIUM] Mozilla Foundation Security Advisory 2022-38: CVE-2022-3034
Mozilla Foundation Security Advisory 2022-38
CVE: CVE-2022-3034
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 102.2.1
Mozilla
Mozilla Foundation Security Advisory 2022-39: CVE-2022-3034
vendor_mozilla·CVSS 4.3
CVE-2022-3034 [MEDIUM] Mozilla Foundation Security Advisory 2022-39: CVE-2022-3034
Mozilla Foundation Security Advisory 2022-39
CVE: CVE-2022-3034
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 91.13.1
GHSA
GHSA-wrfx-qxxc-92rj: When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent
ghsa_unreviewed·2022-12-22
CVE-2022-3034 [MEDIUM] CWE-1021 GHSA-wrfx-qxxc-92rj: When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
OSV
CVE-2022-3034: When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent
osv·2022-12-22·CVSS 4.3
CVE-2022-3034 [MEDIUM] CVE-2022-3034: When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent
When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
OSV
thunderbird vulnerabilities
osv·2022-10-07·CVSS 8.8
CVE-2022-2505 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
spoof the mouse pointer position, obtain sensitive information, spoof the
contents of the addressbar, bypass security restrictions, or execute
arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319,
CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477,
CVE-2022-38478)
Multiple security issues were discovered in Thunderbird. An attacker could
potentially exploit these in order to determine when a user opens a
specially crafted message. (CVE-2022-3032, CVE-2022-3034)
It was discovered that Thunderbird did not correctly handle HTML
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1745751https://www.mozilla.org/security/advisories/mfsa2022-38/https://www.mozilla.org/security/advisories/mfsa2022-39/https://bugzilla.mozilla.org/show_bug.cgi?id=1745751https://www.mozilla.org/security/advisories/mfsa2022-38/https://www.mozilla.org/security/advisories/mfsa2022-39/
2022-12-22
Published