[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-4570Date: (C)2006-09-15   (M)2023-12-22


Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1016866
SECTRACK-1016867
BID-20042
20060901-01-P
SECUNIA-21915
SECUNIA-21916
SECUNIA-21939
SECUNIA-21940
SECUNIA-22036
SECUNIA-22055
SECUNIA-22056
SECUNIA-22074
SECUNIA-22088
SECUNIA-22247
SECUNIA-22274
SECUNIA-22299
SECUNIA-22342
SECUNIA-22391
DSA-1191
DSA-1192
GLSA-200610-01
GLSA-200610-04
MDKSA-2006:169
RHSA-2006:0676
RHSA-2006:0677
SUSE-SA:2006:054
USN-350-1
USN-352-1
USN-361-1
http://www.mozilla.org/security/announce/2006/mfsa2006-63.html
thunderbird-seamonkey-xbl-code-execution(28962)

CPE    2
cpe:/a:mozilla:thunderbird:1.5.0.6
cpe:/a:mozilla:seamonkey:1.0.4

© SecPod Technologies