CVE-2004-0909
Description
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
Risk Information
Base Score
7.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Score
Exploitation Probability
6.561
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in Mozilla Thunderbird 0.7.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.7.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 0.7.2 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-315938 | Mozilla Thunderbird (68.12.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234