CVE-2018-5162: High severity Mozilla Thunderbird vulnerability
Last updated 25 August 2025
Other sources
Plaintext of decrypted emails can leak through the src attribute of remote images, or links.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5162?
CVE-2018-5162 is a vulnerability where plaintext of decrypted emails can leak through the src attribute of remote images or links.
Which software versions are affected by CVE-2018-5162?
Thunderbird ESR < 52.8 and Thunderbird < 52.8 are affected by CVE-2018-5162.
What is the severity of CVE-2018-5162?
CVE-2018-5162 has a severity value of 7.5, which is considered high.
How can I fix CVE-2018-5162?
To fix CVE-2018-5162, update Thunderbird to version 52.8 or later.
Where can I find more information about CVE-2018-5162?
You can find more information about CVE-2018-5162 on the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1457721), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/), [SecurityFocus](http://www.securityfocus.com/bid/104240).