mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-08-13T16:00:00
Updated: 2024-08-07T11:49:02.459Z
Reserved: 2009-08-13T00:00:00
Link: CVE-2008-6961
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-08-13T16:30:00.890
Modified: 2018-10-30T16:25:58.530
Link: CVE-2008-6961
Redhat
No data.