mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T11:49:02.459Z
Reserved: 2009-08-13T00:00:00
Link: CVE-2008-6961

No data.

Status : Deferred
Published: 2009-08-13T16:30:00.890
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-6961

No data.

No data.