CVE-2020-15685

CVSS v3.1 8.8 (High)
88% Progress
EPSS 0.16 % (53th)
0.16% Progress
Affected Products 1
Advisories 15

During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.

Weaknesses
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2022-12-22 20:15:11
(21 months ago)
Updated Date
2023-01-04 14:14:21
(20 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Thunderbird prior 78.7.0 version cpe:2.3:a:mozilla:thunderbird < 78.7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...