Vulnerability Details CVE-2005-0148
Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2005-0148
-
cpe:2.3:a:mozilla:thunderbird:0.6
-
cpe:2.3:a:mozilla:thunderbird:0.7
-
cpe:2.3:a:mozilla:thunderbird:0.8