7.8
CVSSv3

CVE-2022-3155

Published: 22/12/2022 Updated: 30/12/2022
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

Vendor Advisories

Mozilla Foundation Security Advisory 2022-42 Security Vulnerabilities fixed in Thunderbird 1023 Announced September 20, 2022 Impact high Products Thunderbird Fixed in Thunderbird 1023 ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...