Summary
This host is installed with Mozilla Thunderbird and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow attackers to inject scripts and bypass certain security restrictions.
Impact Level: Application
Solution
Upgrade to Thunderbird version to 16.0.2 or later, http://www.mozilla.org/en-US/thunderbird
Insight
Multiple errors
- When handling the 'window.location' object.
- Within CheckURL() function of the 'window.location' object, which can be forced to return the wrong calling document and principal.
- Within handling of 'Location' object can be exploited to bypass security wrapper protection.
Affected
Thunderbird version before 16.0.2 on Windows
References
Severity
Classification
-
CVE CVE-2012-4194, CVE-2012-4195, CVE-2012-4196 -
CVSS Base Score: 5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe Reader Multiple Unspecified Vulnerabilities Jun06 (Windows)
- Asterisk SIP Response Username Enumeration Remote Information Disclosure Vulnerability
- Apple Safari Webkit Multiple Vulnerabilities - May13 (Mac OS X)
- Adobe Reader Old Plugin Signature Bypass Vulnerability (Windows)
- Apple Safari Secure Cookie Security Bypass Vulnerability (Mac OS X)