PoC Index

CVE-2006-0884

HIGH 9.3EPSS 7.2%

The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
7.23% chance of exploitation in the next 30 days, 94th percentile
Published
2006-02-24
Updated
2024-08-07

ExploitDB entries (1)

References

Related