Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2006-0884

N/A

The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.

EPSS 7.07% above median percentile 93.6%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (18)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
≤1.0.7
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
View on NVD ↗ Advisory · secunia.com Advisory · www.mozilla.org Advisory · www.vupen.com