KLA11549
Multiple vulnerabilities in Mozilla Thunderbird

Обновлено: 03/06/2020
Дата обнаружения
27/08/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, spoof user interface, perform cross-site scripting attack, cause denial of service, and obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Multiple memory corruption vulnerabilities can be exploited to execute arbitrary code;
  2. Multiple vulnerabilities can be exploited to bypass security restrictions;
  3. A domain spoofing vulnerability can be exploited to spoof user interface;
  4. A character encoding vulnerability can be exploited to perform cross-site scripting attacks;
  5. A vulnerability can be exploited to cause denial of service;
  6. A cookie leakage vulnerability can be exploited to obtain sensitive information;
Пораженные продукты

Mozilla Thunderbird earlier than 68

Решение

Update to the latest version
Download Mozilla Thunderbird

Первичный источник обнаружения
mfsa2019-28
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

XSS/CSS 
[?]

SUI 
[?]
Связанные продукты
Mozilla Thunderbird
CVE-IDS
CVE-2019-117147.5Critical
CVE-2019-117167.5Critical
CVE-2019-117204.3Warning
CVE-2019-117214.3Warning
CVE-2019-117235.0Critical
CVE-2019-117245.8High
CVE-2019-117254.0Warning
CVE-2019-117275.0Critical
CVE-2019-117284.3Warning
CVE-2019-117107.5Critical
Узнай статистику распространения уязвимостей в твоем регионе