CVE-2005-0149

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
References
Link Resource
http://secunia.com/advisories/19823
http://www.mozilla.org/security/announce/mfsa2005-11.html Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.redhat.com/support/errata/RHSA-2005-094.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-323.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-335.html Patch Vendor Advisory
http://www.securityfocus.com/bid/12407
https://bugzilla.mozilla.org/show_bug.cgi?id=268107 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/19172
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407
http://secunia.com/advisories/19823
http://www.mozilla.org/security/announce/mfsa2005-11.html Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.redhat.com/support/errata/RHSA-2005-094.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-323.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-335.html Patch Vendor Advisory
http://www.securityfocus.com/bid/12407
https://bugzilla.mozilla.org/show_bug.cgi?id=268107 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/19172
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://secunia.com/advisories/19823 - () http://secunia.com/advisories/19823 -
References () http://www.mozilla.org/security/announce/mfsa2005-11.html - Patch, Vendor Advisory () http://www.mozilla.org/security/announce/mfsa2005-11.html - Patch, Vendor Advisory
References () http://www.novell.com/linux/security/advisories/2006_04_25.html - () http://www.novell.com/linux/security/advisories/2006_04_25.html -
References () http://www.redhat.com/support/errata/RHSA-2005-094.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2005-094.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2005-323.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2005-323.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2005-335.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2005-335.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/12407 - () http://www.securityfocus.com/bid/12407 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=268107 - Patch, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=268107 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/19172 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/19172 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407 -

Information

Published : 2005-02-15 05:00

Updated : 2024-11-20 23:54


NVD link : CVE-2005-0149

Mitre link : CVE-2005-0149

CVE.ORG link : CVE-2005-0149


JSON object : View

Products Affected

mozilla

  • thunderbird
  • mozilla