Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*
- < 147.0.1
- < 140.7.1
A vulnerability exists in Mozilla Thunderbird versions prior to 147.0.1 and prior to 140.7.1, allowing for CSS-based exfiltration of content from partially encrypted emails when remote content is permitted. This issue could lead to unauthorized access to sensitive information within the emails.
Exploitation of this vulnerability could result in the unauthorized exfiltration of content from partially encrypted emails, potentially exposing sensitive information.
Users can upgrade to Thunderbird version 147.0.1 or 140.7.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.