Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2022-3032

MEDIUM 6.5

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS 0.66% exploit very unlikely percentile 48.4%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
<91.13.1
mozilla thunderbird
All platforms (wildcard)
≥102.0 <102.2.1
View on NVD ↗ Advisory · www.mozilla.org