4.3

CVE-2014-2018

Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in a (1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.

Data is provided by the National Vulnerability Database (NVD)
MozillaThunderbird Esr Version17.0
MozillaThunderbird Esr Version17.0.1
MozillaThunderbird Esr Version17.0.2
MozillaThunderbird Esr Version17.0.3
MozillaThunderbird Esr Version17.0.4
MozillaThunderbird Esr Version17.0.5
MozillaThunderbird Esr Version17.0.6
MozillaThunderbird Esr Version17.0.7
MozillaThunderbird Esr Version17.0.8
MozillaThunderbird Esr Version17.0.10
MozillaThunderbird Version17.0
MozillaThunderbird Version17.0.1
MozillaThunderbird Version17.0.2
MozillaThunderbird Version17.0.3
MozillaThunderbird Version17.0.4
MozillaThunderbird Version17.0.5
MozillaThunderbird Version17.0.6
MozillaThunderbird Version17.0.7
MozillaThunderbird Version17.0.8
MozillaSeamonkey Version <= 2.19
MozillaSeamonkey Version1.0
MozillaSeamonkey Version1.0 Updatealpha
MozillaSeamonkey Version1.0 Updatebeta
MozillaSeamonkey Version1.0.1
MozillaSeamonkey Version1.0.2
MozillaSeamonkey Version1.0.3
MozillaSeamonkey Version1.0.4
MozillaSeamonkey Version1.0.5
MozillaSeamonkey Version1.0.6
MozillaSeamonkey Version1.0.7
MozillaSeamonkey Version1.0.8
MozillaSeamonkey Version1.0.9
MozillaSeamonkey Version1.1
MozillaSeamonkey Version1.1 Updatealpha
MozillaSeamonkey Version1.1 Updatebeta
MozillaSeamonkey Version1.1.1
MozillaSeamonkey Version1.1.2
MozillaSeamonkey Version1.1.3
MozillaSeamonkey Version1.1.4
MozillaSeamonkey Version1.1.5
MozillaSeamonkey Version1.1.6
MozillaSeamonkey Version1.1.7
MozillaSeamonkey Version1.1.8
MozillaSeamonkey Version1.1.9
MozillaSeamonkey Version1.1.10
MozillaSeamonkey Version1.1.11
MozillaSeamonkey Version1.1.12
MozillaSeamonkey Version1.1.13
MozillaSeamonkey Version1.1.14
MozillaSeamonkey Version1.1.15
MozillaSeamonkey Version1.1.16
MozillaSeamonkey Version1.1.17
MozillaSeamonkey Version1.1.18
MozillaSeamonkey Version1.1.19
MozillaSeamonkey Version1.5.0.8
MozillaSeamonkey Version1.5.0.9
MozillaSeamonkey Version1.5.0.10
MozillaSeamonkey Version2.0
MozillaSeamonkey Version2.0 Updatealpha_1
MozillaSeamonkey Version2.0 Updatealpha_2
MozillaSeamonkey Version2.0 Updatealpha_3
MozillaSeamonkey Version2.0 Updatebeta_1
MozillaSeamonkey Version2.0 Updatebeta_2
MozillaSeamonkey Version2.0 Updaterc1
MozillaSeamonkey Version2.0 Updaterc2
MozillaSeamonkey Version2.0.1
MozillaSeamonkey Version2.0.2
MozillaSeamonkey Version2.0.3
MozillaSeamonkey Version2.0.4
MozillaSeamonkey Version2.0.5
MozillaSeamonkey Version2.0.6
MozillaSeamonkey Version2.0.7
MozillaSeamonkey Version2.0.8
MozillaSeamonkey Version2.0.9
MozillaSeamonkey Version2.0.10
MozillaSeamonkey Version2.0.11
MozillaSeamonkey Version2.0.12
MozillaSeamonkey Version2.0.13
MozillaSeamonkey Version2.0.14
MozillaSeamonkey Version2.1
MozillaSeamonkey Version2.1 Updatealpha1
MozillaSeamonkey Version2.1 Updatealpha2
MozillaSeamonkey Version2.1 Updatealpha3
MozillaSeamonkey Version2.1 Updatebeta1
MozillaSeamonkey Version2.1 Updatebeta2
MozillaSeamonkey Version2.1 Updatebeta3
MozillaSeamonkey Version2.1 Updaterc1
MozillaSeamonkey Version2.1 Updaterc2
MozillaSeamonkey Version2.10
MozillaSeamonkey Version2.10 Updatebeta1
MozillaSeamonkey Version2.10 Updatebeta2
MozillaSeamonkey Version2.10 Updatebeta3
MozillaSeamonkey Version2.10.1
MozillaSeamonkey Version2.11
MozillaSeamonkey Version2.11 Updatebeta1
MozillaSeamonkey Version2.11 Updatebeta2
MozillaSeamonkey Version2.11 Updatebeta3
MozillaSeamonkey Version2.11 Updatebeta4
MozillaSeamonkey Version2.11 Updatebeta5
MozillaSeamonkey Version2.11 Updatebeta6
MozillaSeamonkey Version2.12
MozillaSeamonkey Version2.12 Updatebeta1
MozillaSeamonkey Version2.12 Updatebeta2
MozillaSeamonkey Version2.12 Updatebeta3
MozillaSeamonkey Version2.12 Updatebeta4
MozillaSeamonkey Version2.12 Updatebeta5
MozillaSeamonkey Version2.12 Updatebeta6
MozillaSeamonkey Version2.12.1
MozillaSeamonkey Version2.13
MozillaSeamonkey Version2.13 Updatebeta1
MozillaSeamonkey Version2.13 Updatebeta2
MozillaSeamonkey Version2.13 Updatebeta3
MozillaSeamonkey Version2.13 Updatebeta4
MozillaSeamonkey Version2.13 Updatebeta5
MozillaSeamonkey Version2.13 Updatebeta6
MozillaSeamonkey Version2.13.1
MozillaSeamonkey Version2.13.2
MozillaSeamonkey Version2.14
MozillaSeamonkey Version2.14 Updatebeta1
MozillaSeamonkey Version2.14 Updatebeta2
MozillaSeamonkey Version2.14 Updatebeta3
MozillaSeamonkey Version2.14 Updatebeta4
MozillaSeamonkey Version2.14 Updatebeta5
MozillaSeamonkey Version2.15
MozillaSeamonkey Version2.15 Updatebeta1
MozillaSeamonkey Version2.15 Updatebeta2
MozillaSeamonkey Version2.15 Updatebeta3
MozillaSeamonkey Version2.15 Updatebeta4
MozillaSeamonkey Version2.15 Updatebeta5
MozillaSeamonkey Version2.15 Updatebeta6
MozillaSeamonkey Version2.15.1
MozillaSeamonkey Version2.15.2
MozillaSeamonkey Version2.16
MozillaSeamonkey Version2.16 Updatebeta1
MozillaSeamonkey Version2.16 Updatebeta2
MozillaSeamonkey Version2.16 Updatebeta3
MozillaSeamonkey Version2.16 Updatebeta4
MozillaSeamonkey Version2.16 Updatebeta5
MozillaSeamonkey Version2.16.1
MozillaSeamonkey Version2.16.2
MozillaSeamonkey Version2.17
MozillaSeamonkey Version2.17 Updatebeta1
MozillaSeamonkey Version2.17 Updatebeta2
MozillaSeamonkey Version2.17 Updatebeta3
MozillaSeamonkey Version2.17 Updatebeta4
MozillaSeamonkey Version2.17.1
MozillaSeamonkey Version2.18 Updatebeta1
MozillaSeamonkey Version2.18 Updatebeta2
MozillaSeamonkey Version2.18 Updatebeta3
MozillaSeamonkey Version2.18 Updatebeta4
MozillaSeamonkey Version2.19 Updatebeta1
MozillaSeamonkey Version2.19 Updatebeta2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.73% 0.704
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.