CVE-2022-3032

6.5
MEDIUMCVSS v3.1 Base Score
0.68%
LOW RiskEPSS (51st percentile)

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

Published: 12/22/2022
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

0.68%LOW Exploitation Risk
51st percentile

This vulnerability has a 0.68% probability of being exploited in the next 30 days, ranking higher than 51% of all scored CVEs.

CWE Classification

Advertisement