5
CVSSv2

CVE-2017-7848

Published: 11/06/2018 Updated: 09/08/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

redhat enterprise linux 6.0

redhat enterprise linux 7.0

redhat enterprise linux desktop 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server 6.0

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.3

redhat enterprise linux server aus 7.4

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

redhat enterprise linux workstation 6.0

redhat enterprise linux workstation 7.0

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerab ...
RSS fields can inject new lines into the created email structure, modifying the message body This vulnerability affects Thunderbird &lt; 5252 ...
Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service, information disclosure or spoofing of sender's email addresses For the oldstable distribution (jessie), these problems have been fixed in version 1:5252-2~deb8u1 For the stable distribution (stretch), these problems hav ...
Security vulnerabilities fixed in Thunderbird 5252 Announced December 22, 2017 Impact critical Products Thunderbird Fixed in Thunderbird 5252 ...
Several security issues were fixed in Thunderbird ...
Oracle Linux Bulletin - January 2018 Description The Oracle Linux Bulletin lists all CVEs that had been resolved and announced in Oracle Linux Security Advisories (ELSA) in the last one month prior to the release of the bulletin Oracle Linux Bulletins are published on the same day as Oracle Critical ...
Oracle Solaris Third Party Bulletin - January 2018 Description The Oracle Solaris Third Party Bulletin announces patches for one or more security vulnerabilities fixed in third party software that is included in Oracle Solaris distributions Starting January 20, 2015, Third Party Bulletins are released on the same day when Oracle Critica ...

Recent Articles

Mozilla Patches Critical Bug in Thunderbird
Threatpost • Tom Spring • 26 Dec 2017

Mozilla issued a critical security update to its popular open-source Thunderbird email client. The patch was part of a December release of five fixes that included two bugs rated high and one rated moderate and another low.
Mozilla said Thunderbird, which is also serves as a news, RSS and chat client, the latest Thunderbird 52.5.2 version released last week fixes the vulnerabilities.
The most serious of the fixes is a critical buffer overflow bug (CVE-2017-7845) impacting Thunderbird...