mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2009-08-13T16:00:00
Updated: 2024-08-07T11:49:02.459Z
Reserved: 2009-08-13T00:00:00
Link: CVE-2008-6961

No data.

Status : Deferred
Published: 2009-08-13T16:30:00.890
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-6961

No data.