Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.826722
Category:General
Title:Mozilla Thunderbird Security Advisories (MFSA2022-50, MFSA2022-50) - Mac OS X
Summary:Mozilla Thunderbird is prone to a security; bypass vulnerability.
Description:Summary:
Mozilla Thunderbird is prone to a security
bypass vulnerability.

Vulnerability Insight:
The flaw exists when a Thunderbird user quoted
from an HTML email and the email contained either a VIDEO tag with the POSTER
attribute or an OBJECT tag with a DATA attribute, a network request to the
referenced remote URL was performed, regardless of a configuration to block
remote content.

Vulnerability Impact:
Successful exploitation will allow
attackers to execute JavaScript code included in the message in the context
of the message compose document, read and modify the contents of the message
compose document, including the quoted original message, which could potentially
contain the decrypted plaintext of encrypted data in the crafted email.

Affected Software/OS:
Mozilla Thunderbird version before
102.5.1 on Mac OS X.

Solution:
Upgrade to Mozilla Thunderbird version 102.5.1
or later, Please see the references for more information.

CVSS Score:
9.4

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-45414
https://bugzilla.mozilla.org/show_bug.cgi?id=1788096
https://www.mozilla.org/security/advisories/mfsa2022-50/
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.