Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2005-3402

N/A

EN The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.

EPSS 1.06% au-dessus de la médiane percentile 61.4%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (2)
Vendor Produit Versions
mozilla thunderbird
Toutes plateformes (wildcard)
mozilla thunderbird
Toutes plateformes (wildcard)
Voir sur NVD ↗