thunderbird/thunderbird-android

thunderbird/thunderbird-android

Releases655
Frequency1 week 2 days
Last Release
Stars13.6K
Thunderbird for Android – Open Source Email App for Android (fka K-9 Mail)

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM4.3 MEDIUM

K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain valid S/MIME or PGP signatures for arbitrary content to be displayed to a third party. NOTE: the vendor states "We don't plan to take any action because of this."

7.5 HIGH

K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious WebDAV server or intercept the reponse of a valid WebDAV server.