Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2021-23992

CVE-2021-23992, sévérité medium (CVSS 4.3) : 1 app suivie concernée, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
4.3

Échelle NVD

Exploitation
0.5 %

EPSS, prédiction à 30 jours

Apps suivies
1
Encore exposées
0

EN Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

Vecteur d'attaque : Réseau Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS 0.48% exploit très peu probable percentile 38.9%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (1)
Vendor Produit Versions
mozilla thunderbird
Toutes plateformes (wildcard)
<78.9.1
Voir sur NVD ↗ Advisory · bugzilla.mozilla.org Advisory · www.mozilla.org

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa