CVE-2008-6961
mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1)…
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/seamonkey · mozilla/thunderbird
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32714Vendor Advisory
- http://secunia.com/advisories/32715Vendor Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-59.htmlVendor Advisory
- http://www.securityfocus.com/bid/32363
- http://www.securitytracker.com/id?1021247
- https://bugzilla.mozilla.org/show_bug.cgi?id=458883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46734
- http://secunia.com/advisories/32714Vendor Advisory
- http://secunia.com/advisories/32715Vendor Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-59.htmlVendor Advisory
- http://www.securityfocus.com/bid/32363
- http://www.securitytracker.com/id?1021247
- https://bugzilla.mozilla.org/show_bug.cgi?id=458883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46734
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.