CVE-2006-0884 describes a critical vulnerability in Mozilla Thunderbird 1.0.7 and earlier, where its WYSIWYG rendering engine allows user-assisted attackers to bypass JavaScript security. By sending an email with a JavaScript URI in an IFRAME's SRC attribute, an attacker can execute arbitrary code, leading to information disclosure or application crashes when the user edits the email. This vulnerability carries a CVSS score of 9.3, indicating a high severity with network-based attacks and medium complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists, and despite its age and high risk score, it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.7CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:* | ||
0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:0.2:*:*:*:*:*:*:* | ||
0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:0.3:*:*:*:*:*:*:* | ||
0.4CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.