CVE-2021-29969

CVSS v3.1 5.9 (Medium)
59% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.16 % (53th)
0.16% Progress
Affected Products 1
Advisories 16

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.

Weaknesses
CWE-552
Files or Directories Accessible to External Parties
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2021-08-05 20:15:08
(3 years ago)
Updated Date
2022-12-09 19:03:59
(21 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Thunderbird prior 78.12 version cpe:2.3:a:mozilla:thunderbird < 78.12
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...