CVE-2006-0884
HIGH 9.3EPSS 7.2%
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 7.23% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2006-02-24
- Updated
- 2024-08-07