Unrated severityNVD Advisory· Published Feb 15, 2005· Updated Jun 16, 2026
CVE-2005-0149
CVE-2005-0149
Description
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*
- (no CPE)range: >=1.7, <=1.7.3
cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*
- (no CPE)range: >=0.6, <=0.9
Patches
Vulnerability mechanics
References
11- www.mozilla.org/security/announce/mfsa2005-11.htmlnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2005-094.htmlnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2005-323.htmlnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2005-335.htmlnvdPatchVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPatchVendor Advisory
- secunia.com/advisories/19823nvd
- www.novell.com/linux/security/advisories/2006_04_25.htmlnvd
- www.securityfocus.com/bid/12407nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19172nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100047nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11407nvd
News mentions
0No linked articles in our index yet.