Show filters
264 Total Results
Displaying 261-264 of 264
Sort by:
Attacker Value
Unknown
CVE-2006-0884
Disclosure Date: February 24, 2006 (last updated February 22, 2025)
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
0
Attacker Value
Unknown
CVE-2006-0294
Disclosure Date: February 02, 2006 (last updated February 22, 2025)
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
0
Attacker Value
Unknown
CVE-2006-0236
Disclosure Date: January 18, 2006 (last updated February 22, 2025)
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.
0
Attacker Value
Unknown
CVE-2005-2602
Disclosure Date: August 17, 2005 (last updated February 22, 2025)
Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.
0