This commit is contained in:
Tom Ritter 2024-11-13 08:41:39 -05:00
Родитель b9f0167cf9
Коммит 9769b062ea
3 изменённых файлов: 32 добавлений и 0 удалений

Просмотреть файл

@ -4,6 +4,8 @@ impact: high
fixed_in:
- Thunderbird 132
title: Security Vulnerabilities fixed in Thunderbird 132
description: |
*In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.*
advisories:
CVE-2024-10458:
title: Permission leak via embed or object elements

Просмотреть файл

@ -0,0 +1,15 @@
## mfsa2024-61.yml
announced: Nov 12, 2024
impact: high
fixed_in:
- Thunderbird 128.4.3
title: Security Vulnerabilities fixed in Thunderbird 128.4.3
advisories:
CVE-2024-11159:
title: Potential disclosure of plaintext in OpenPGP encrypted message
impact: high
reporter: Several reporters
description: |
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext.
bugs:
- url: 1925929

Просмотреть файл

@ -0,0 +1,15 @@
## mfsa2024-62.yml
announced: Nov 12, 2024
impact: high
fixed_in:
- Thunderbird 132.0.1
title: Security Vulnerabilities fixed in Thunderbird 132.0.1
advisories:
CVE-2024-11159:
title: Potential disclosure of plaintext in OpenPGP encrypted message
impact: high
reporter: Several reporters
description: |
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext.
bugs:
- url: 1925929