4.3
CVE-2008-6961
- EPSS 1.52%
- Veröffentlicht 13.08.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:03:19
- Erkennungen
mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version <= 2.0.0.17
Mozilla ≫ Thunderbird Version 0.1
Mozilla ≫ Thunderbird Version 0.2
Mozilla ≫ Thunderbird Version 0.3
Mozilla ≫ Thunderbird Version 0.4
Mozilla ≫ Thunderbird Version 0.5
Mozilla ≫ Thunderbird Version 0.6
Mozilla ≫ Thunderbird Version 0.7
Mozilla ≫ Thunderbird Version 0.7.1
Mozilla ≫ Thunderbird Version 0.7.2
Mozilla ≫ Thunderbird Version 0.7.3
Mozilla ≫ Thunderbird Version 0.8
Mozilla ≫ Thunderbird Version 0.9
Mozilla ≫ Thunderbird Version 1.0
Mozilla ≫ Thunderbird Version 1.0.1
Mozilla ≫ Thunderbird Version 1.0.2
Mozilla ≫ Thunderbird Version 1.0.3
Mozilla ≫ Thunderbird Version 1.0.4
Mozilla ≫ Thunderbird Version 1.0.5
Mozilla ≫ Thunderbird Version 1.0.5 Update beta
Mozilla ≫ Thunderbird Version 1.0.7
Mozilla ≫ Thunderbird Version 1.0.8
Mozilla ≫ Thunderbird Version 1.5
Mozilla ≫ Thunderbird Version 1.5 Update beta2
Mozilla ≫ Thunderbird Version 1.5.0.1
Mozilla ≫ Thunderbird Version 1.5.0.2
Mozilla ≫ Thunderbird Version 1.5.0.3
Mozilla ≫ Thunderbird Version 1.5.0.4
Mozilla ≫ Thunderbird Version 1.5.0.5
Mozilla ≫ Thunderbird Version 1.5.0.6
Mozilla ≫ Thunderbird Version 1.5.0.7
Mozilla ≫ Thunderbird Version 1.5.0.8
Mozilla ≫ Thunderbird Version 1.5.0.9
Mozilla ≫ Thunderbird Version 1.5.0.10
Mozilla ≫ Thunderbird Version 1.5.0.11
Mozilla ≫ Thunderbird Version 1.5.0.12
Mozilla ≫ Thunderbird Version 1.5.0.13
Mozilla ≫ Thunderbird Version 1.5.0.14
Mozilla ≫ Thunderbird Version 1.5.1
Mozilla ≫ Thunderbird Version 1.5.2
Mozilla ≫ Thunderbird Version 1.7.1
Mozilla ≫ Thunderbird Version 1.7.3
Mozilla ≫ Thunderbird Version 2.0
Mozilla ≫ Thunderbird Version 2.0.0.0
Mozilla ≫ Thunderbird Version 2.0.0.1
Mozilla ≫ Thunderbird Version 2.0.0.2
Mozilla ≫ Thunderbird Version 2.0.0.3
Mozilla ≫ Thunderbird Version 2.0.0.4
Mozilla ≫ Thunderbird Version 2.0.0.5
Mozilla ≫ Thunderbird Version 2.0.0.6
Mozilla ≫ Thunderbird Version 2.0.0.7
Mozilla ≫ Thunderbird Version 2.0.0.8
Mozilla ≫ Thunderbird Version 2.0.0.9
Mozilla ≫ Thunderbird Version 2.0.0.11
Mozilla ≫ Thunderbird Version 2.0.0.12
Mozilla ≫ Thunderbird Version 2.0.0.13
Mozilla ≫ Thunderbird Version 2.0.0.14
Mozilla ≫ Thunderbird Version 2.0.0.15
Mozilla ≫ Thunderbird Version 2.0.0.16
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.52% | 0.713 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://secunia.com/advisories/32714
http://secunia.com/advisories/32715
http://www.mozilla.org/security/announce/2008/mfsa2008-59.html
http://www.securityfocus.com/bid/32363
http://www.securitytracker.com/id?1021247
https://bugzilla.mozilla.org/show_bug.cgi?id=458883
https://exchange.xforce.ibmcloud.com/vulnerabilities/46734