Vulnerabilities
Vulnerable Software
Mozilla:  >> Thunderbird  >> 0.9  Security Vulnerabilities
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
CVSS Score
5.0
EPSS Score
0.017
Published
2005-05-02
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
CVSS Score
5.0
EPSS Score
0.017
Published
2005-02-15


Contact Us

Shodan ® - All rights reserved