Vulnerability · NVD
CVE-2006-4570
N/A
Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.
EPSS
2.25%
above median
percentile 81.3%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | ≤1.5.0.6 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |