Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-05-01 21:00
Updated : 2017-10-10 18:29
NVD link : CVE-2005-0148
Mitre link : CVE-2005-0148
JSON object : View
CWE
Products Affected
mozilla
- thunderbird