[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1393 --- thunderbird

ID: oval:org.secpod.oval:def:1700304Date: (C)2020-02-20   (M)2023-12-20
Class: PATCHFamily: unix




When pasting a lt;stylegt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR CVE-2019-17016

Platform:
Amazon Linux 2
Product:
thunderbird
Reference:
ALAS2-2020-1393
CVE-2019-17017
CVE-2019-17016
CVE-2019-17024
CVE-2019-17022
CVE-2019-17026
CVE    5
CVE-2019-17017
CVE-2019-17024
CVE-2019-17026
CVE-2019-17016
...
CPE    2
cpe:/a:mozilla:thunderbird
cpe:/o:amazon:linux:2

© SecPod Technologies