Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/19823 - | |
References | () http://www.mozilla.org/security/announce/mfsa2005-11.html - Patch, Vendor Advisory | |
References | () http://www.novell.com/linux/security/advisories/2006_04_25.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2005-094.html - Patch, Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2005-323.html - Patch, Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2005-335.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/12407 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=268107 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/19172 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407 - |
Information
Published : 2005-02-15 05:00
Updated : 2024-11-20 23:54
NVD link : CVE-2005-0149
Mitre link : CVE-2005-0149
CVE.ORG link : CVE-2005-0149
JSON object : View
Products Affected
mozilla
- thunderbird
- mozilla
CWE