Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | |||
Test ID: | 1.3.6.1.4.1.25623.1.0.900910 |
Category: | General |
Title: | Mozilla Products Information Disclosure Vulnerability (Windows) |
Summary: | The host is installed with Thunderbird/Seamonkey and is prone to; Information Disclosure vulnerability. |
Description: | Summary: The host is installed with Thunderbird/Seamonkey and is prone to Information Disclosure vulnerability. Vulnerability Insight: A flaw exists in the JavaScript code embedded in mailnews which can be exploited using scripts which read the '.documentURI' or '.textContent' DOM properties. Vulnerability Impact: Successful exploitation will let the attackers obtain the mailbox URI of the recipient or disclose comments placed in a forwarded email. Affected Software/OS: Seamonkey version prior to 1.1.13 and Thunderbird version prior to 2.0.0.18 on Windows. Solution: Upgrade to Seamonkey version 1.1.13 or later Upgrade to Thunderbird version 2.0.0.18 or later. CVSS Score: 4.3 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N |
Cross-Ref: |
BugTraq ID: 32363 Common Vulnerability Exposure (CVE) ID: CVE-2008-6961 http://www.securityfocus.com/bid/32363 http://www.securitytracker.com/id?1021247 http://secunia.com/advisories/32714 http://secunia.com/advisories/32715 XForce ISS Database: mozilla-domproperties-info-disclosure(46734) https://exchange.xforce.ibmcloud.com/vulnerabilities/46734 |
Copyright | Copyright (C) 2009 Greenbone Networks GmbH |
This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |