CVE-2018-5184: Weak Encryption
Last updated 25 August 2025
Other sources
Using remote content in encrypted messages can lead to the disclosure of plaintext.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5184?
CVE-2018-5184 is a vulnerability that allows the disclosure of plaintext when using remote content in encrypted messages in Thunderbird ESR < 52.8 and Thunderbird < 52.8.
What is the severity of CVE-2018-5184?
CVE-2018-5184 has a severity level of high.
Which software versions are affected by CVE-2018-5184?
CVE-2018-5184 affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Are there any references available for CVE-2018-5184?
Yes, you can find references for CVE-2018-5184 at the following links: [reference 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1411592), [reference 2](https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/), [reference 3](http://www.securityfocus.com/bid/104240).
How can I fix CVE-2018-5184?
To fix CVE-2018-5184, update Thunderbird to version 52.8 or higher.