PT-2005-1249 · Mozilla+1 · Thunderbird+2

Tom Braun

·

Published

2005-01-29

·

Updated

2017-10-11

·

CVE-2005-0148

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 0.9
Description The issue arises when Thunderbird, running on Windows systems, processes javascript: links. It uses the default handler, which invokes Internet Explorer. This may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer installed on the user's system.
Recommendations For Thunderbird versions prior to 0.9, consider updating to a version that properly handles javascript: links without invoking Internet Explorer, or restrict the use of javascript: links in Thunderbird until a proper fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0148

Affected Products

Internet Explorer
Thunderbird
Windows