Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect.
| Software | From | Fixed in |
|---|---|---|
| mozilla / thunderbird | - | 24.7.x |
| mozilla / thunderbird | 24.0.1 | 24.0.1.x |
| mozilla / thunderbird | 24.2 | 24.2.x |
| mozilla / firefox | - | 30.0.x |
| mozilla / thunderbird | 24.5 | 24.5.x |
| mozilla / thunderbird | 24.1 | 24.1.x |
| mozilla / thunderbird | 24.1.1 | 24.1.1.x |
| mozilla / thunderbird | 24.4 | 24.4.x |
| mozilla / thunderbird | 24.3 | 24.3.x |
| mozilla / thunderbird | 24.0 | 24.0.x |
| mozilla / thunderbird | 24.6 | 24.6.x |