SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-6961

mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1)…

MEDIUM 4.3EPSS 1.52%

Does this matter?

Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.

Description

mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.52% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
mozilla/seamonkey · mozilla/thunderbird
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.