CVE
- Id
- 17149
- CVE No.
- CVE-2006-1045
- Status
- Candidate
- Description
- The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.
- Phase
- Assigned (20060307)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 140486 | 17149 | CVE-2006-1045 | BUGTRAQ:20060228 Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities | View |
| 140487 | 17149 | CVE-2006-1045 | URL:http://www.securityfocus.com/archive/1/426347 | View |
| 140488 | 17149 | CVE-2006-1045 | CONFIRM:http://www.mozilla.org/security/announce/2006/mfsa2006-26.html | View |
| 140489 | 17149 | CVE-2006-1045 | DEBIAN:DSA-1046 | View |
| 140490 | 17149 | CVE-2006-1045 | URL:http://www.debian.org/security/2006/dsa-1046 | View |
| 140491 | 17149 | CVE-2006-1045 | DEBIAN:DSA-1051 | View |
| 140492 | 17149 | CVE-2006-1045 | URL:http://www.debian.org/security/2006/dsa-1051 | View |
| 140493 | 17149 | CVE-2006-1045 | GENTOO:GLSA-200604-18 | View |
| 140494 | 17149 | CVE-2006-1045 | URL:http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml | View |
| 140495 | 17149 | CVE-2006-1045 | GENTOO:GLSA-200605-09 | View |
| 140496 | 17149 | CVE-2006-1045 | URL:http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml | View |
| 140497 | 17149 | CVE-2006-1045 | HP:HPSBUX02156 | View |
| 140498 | 17149 | CVE-2006-1045 | URL:http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded | View |
| 140499 | 17149 | CVE-2006-1045 | HP:SSRT061236 | View |
| 140500 | 17149 | CVE-2006-1045 | URL:http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded | View |
| 140501 | 17149 | CVE-2006-1045 | MANDRIVA:MDKSA-2006:078 | View |
| 140502 | 17149 | CVE-2006-1045 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:078 | View |
| 140503 | 17149 | CVE-2006-1045 | REDHAT:RHSA-2006:0330 | View |
| 140504 | 17149 | CVE-2006-1045 | URL:http://www.redhat.com/support/errata/RHSA-2006-0330.html | View |
| 140505 | 17149 | CVE-2006-1045 | SUSE:SUSE-SA:2006:022 | View |
| 140506 | 17149 | CVE-2006-1045 | URL:http://www.novell.com/linux/security/advisories/2006_04_25.html | View |
| 140507 | 17149 | CVE-2006-1045 | UBUNTU:USN-276-1 | View |
| 140508 | 17149 | CVE-2006-1045 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-276-1 | View |
| 140509 | 17149 | CVE-2006-1045 | BID:16881 | View |
| 140510 | 17149 | CVE-2006-1045 | URL:http://www.securityfocus.com/bid/16881 | View |
| 140511 | 17149 | CVE-2006-1045 | BID:17516 | View |
| 140512 | 17149 | CVE-2006-1045 | URL:http://www.securityfocus.com/bid/17516 | View |
| 140513 | 17149 | CVE-2006-1045 | OVAL:oval:org.mitre.oval:def:10254 | View |
| 140514 | 17149 | CVE-2006-1045 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10254 | View |
| 140515 | 17149 | CVE-2006-1045 | VUPEN:ADV-2006-1356 | View |
| 140516 | 17149 | CVE-2006-1045 | URL:http://www.vupen.com/english/advisories/2006/1356 | View |
| 140517 | 17149 | CVE-2006-1045 | VUPEN:ADV-2006-3749 | View |
| 140518 | 17149 | CVE-2006-1045 | URL:http://www.vupen.com/english/advisories/2006/3749 | View |
| 140519 | 17149 | CVE-2006-1045 | OVAL:oval:org.mitre.oval:def:1975 | View |
| 140520 | 17149 | CVE-2006-1045 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1975 | View |
| 140521 | 17149 | CVE-2006-1045 | SECUNIA:19821 | View |
| 140522 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/19821 | View |
| 140523 | 17149 | CVE-2006-1045 | SECUNIA:19823 | View |
| 140524 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/19823 | View |
| 140525 | 17149 | CVE-2006-1045 | SECUNIA:19863 | View |
| 140526 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/19863 | View |
| 140527 | 17149 | CVE-2006-1045 | SECUNIA:19902 | View |
| 140528 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/19902 | View |
| 140529 | 17149 | CVE-2006-1045 | SECUNIA:19950 | View |
| 140530 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/19950 | View |
| 140531 | 17149 | CVE-2006-1045 | SECUNIA:19941 | View |
| 140532 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/19941 | View |
| 140533 | 17149 | CVE-2006-1045 | SECUNIA:20051 | View |
| 140534 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/20051 | View |
| 140535 | 17149 | CVE-2006-1045 | SECUNIA:22065 | View |
| 140536 | 17149 | CVE-2006-1045 | URL:http://secunia.com/advisories/22065 | View |
| 140537 | 17149 | CVE-2006-1045 | SREASON:514 | View |
| 140538 | 17149 | CVE-2006-1045 | URL:http://securityreason.com/securityalert/514 | View |
| 140539 | 17149 | CVE-2006-1045 | XF:thunderbird-inline-information-disclosure(24959) | View |