<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.eeye.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Vulnerability Assessment</title><link>http://forums.eeye.com/forums/18.aspx</link><description>Post issues related to your Vulnerability Assessment scans in this forum</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP1 (Build: 30415.43)</generator><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4507.aspx</link><pubDate>Fri, 10 Jul 2009 03:23:32 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4507</guid><dc:creator>vkundakci</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4507.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4507</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;nomuus:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;This should be fixed in the next audits release 2104.&amp;nbsp; Btw, just in case you didn&amp;#39;t get the several annoying notifications from Mozilla like the rest of us (heh:) Firefox 3.5 is now GA.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&amp;nbsp; I did not get anything (annoying or otherwise) from Mozilla but, yes, I am now running 3.5.&amp;nbsp; Maybe I did, but I am used to tuning out nagging notices...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4501.aspx</link><pubDate>Thu, 09 Jul 2009 23:01:58 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4501</guid><dc:creator>nomuus</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4501.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4501</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;vkundakci:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;By the way the header for the first audit was: Mozilla Multiple Vulnerabilities (20090421) - Windows - Thunderbird&lt;/p&gt;
&lt;p&gt;and the second one was: Mozilla Multiple Vulnerabilities (20090611) - Windows - Thunderbird&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sorry, I should have included them...&amp;nbsp; By the way, I do not have Seamonkey. I have Firefox 3.5 RC3 installed.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This should be fixed in the next audits release 2104.&amp;nbsp; Btw, just in case you didn&amp;#39;t get the several annoying notifications from Mozilla like the rest of us (heh:) Firefox 3.5 is now GA.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4500.aspx</link><pubDate>Thu, 09 Jul 2009 22:34:03 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4500</guid><dc:creator>xepiercex</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4500.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4500</wfw:commentRss><description>&lt;p&gt;I just wanted to add that I&amp;#39;m seeing the same here.&amp;nbsp; All the machines in my lab have been updated to Thunderbird 2.0.0.22 and Retina is reporting a false positive on all of them (which is killing my Level 1 vulnerability tally, BTW).&amp;nbsp; Please fix the regular expression in your audit rule ASAP.&amp;nbsp; In the meantime, I&amp;#39;m filtering this rule out of my audits.&amp;nbsp; Thanks!&lt;br /&gt;&lt;br /&gt;Pierce&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4488.aspx</link><pubDate>Mon, 06 Jul 2009 16:53:10 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4488</guid><dc:creator>nomuus</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4488.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4488</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Yes, It will be looked into and updated if necessary. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4485.aspx</link><pubDate>Mon, 06 Jul 2009 02:07:52 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4485</guid><dc:creator>vkundakci</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4485.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4485</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;nomuus:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;It might be flagging since there was no patched version available to correctly determine the fixed level at the time of the audit was written.&amp;nbsp; This is not uncommon with Thunderbird--Historically for the past several security releases, Mozilla has stated a certain version of Thunderbird has been patched in a certain version, but upon going to the main site to download, you are offered a vulnerable version to download.&amp;nbsp;&amp;nbsp; I believe it was their update with Firefox 3.0.11 that stated SeaMonkey and Thunderbird should disable javascript to mitigate vulnerabilities since a fixed version was not&amp;nbsp; yet available.&amp;nbsp; To be quite honest, the audit may simply just need to be updated to detect the patched version--and please beware when using Thunderbird--I highly recommend you disable Javascript since this app is typically not patched in the same timely manner as Firefox is...&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;Thanks.&amp;nbsp; In config editor I see that javascript.enabled is set to false.&amp;nbsp; I don&amp;#39;t see any other places to set this in Thunderbird.&amp;nbsp; Thunderbird 2.0.0.22 just came out recently.&amp;nbsp; So can I assume that the Blink&amp;#39;s audit will be updated?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4476.aspx</link><pubDate>Fri, 03 Jul 2009 18:43:37 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4476</guid><dc:creator>nomuus</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4476.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4476</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;vkundakci:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;bpatten:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;It appears that the audit is looking at the file version:&lt;/p&gt;
&lt;p&gt;%ProgramFiles%\Mozilla Thunderbird\thunderbird.exe&lt;/p&gt;
&lt;p&gt;Can you make sure thunderbird is above 2.0.0.22?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;C:\Program Files\Mozilla Thunderbird\thunderbird.exe properties product version lists as 2.0.0.22, and file version as 1.8.1.22: 2009060502&lt;/p&gt;
&lt;p&gt;C:\Program Files\Mozilla Thunderbird 3 Beta 2\thunderbird,exe properties product version lists as 3.0b2, and file versions as 1.9.1b3pre&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It might be flagging since there was no patched version available to correctly determine the fixed level at the time of the audit was written.&amp;nbsp; This is not uncommon with Thunderbird--Historically for the past several security releases, Mozilla has stated a certain version of Thunderbird has been patched in a certain version, but upon going to the main site to download, you are offered a vulnerable version to download.&amp;nbsp;&amp;nbsp; I believe it was their update with Firefox 3.0.11 that stated SeaMonkey and Thunderbird should disable javascript to mitigate vulnerabilities since a fixed version was not&amp;nbsp; yet available.&amp;nbsp; To be quite honest, the audit may simply just need to be updated to detect the patched version--and please beware when using Thunderbird--I highly recommend you disable Javascript since this app is typically not patched in the same timely manner as Firefox is...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4461.aspx</link><pubDate>Tue, 30 Jun 2009 23:36:41 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4461</guid><dc:creator>vkundakci</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4461.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4461</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;bpatten:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;It appears that the audit is looking at the file version:&lt;/p&gt;
&lt;p&gt;%ProgramFiles%\Mozilla Thunderbird\thunderbird.exe&lt;/p&gt;
&lt;p&gt;Can you make sure thunderbird is above 2.0.0.22?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;C:\Program Files\Mozilla Thunderbird\thunderbird.exe properties product version lists as 2.0.0.22, and file version as 1.8.1.22: 2009060502&lt;/p&gt;
&lt;p&gt;C:\Program Files\Mozilla Thunderbird 3 Beta 2\thunderbird,exe properties product version lists as 3.0b2, and file versions as 1.9.1b3pre&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4458.aspx</link><pubDate>Tue, 30 Jun 2009 03:07:30 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4458</guid><dc:creator>bpatten</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4458.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4458</wfw:commentRss><description>&lt;p&gt;It appears that the audit is looking at the file version:&lt;/p&gt;
&lt;p&gt;%ProgramFiles%\Mozilla Thunderbird\thunderbird.exe&lt;/p&gt;
&lt;p&gt;Can you make sure thunderbird is above 2.0.0.22?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4445.aspx</link><pubDate>Fri, 26 Jun 2009 20:32:23 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4445</guid><dc:creator>vkundakci</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4445.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4445</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;bpatten:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;can you paste the audit findings here in the forum? That&amp;#39;ll help me trace the audit to let you know how we&amp;#39;re detecting it. &lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;By the way the header for the first audit was: Mozilla Multiple Vulnerabilities (20090421) - Windows - Thunderbird&lt;/p&gt;
&lt;p&gt;and the second one was: Mozilla Multiple Vulnerabilities (20090611) - Windows - Thunderbird&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sorry, I should have included them...&amp;nbsp; By the way, I do not have Seamonkey. I have Firefox 3.5 RC3 installed.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4444.aspx</link><pubDate>Fri, 26 Jun 2009 20:26:09 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4444</guid><dc:creator>vkundakci</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4444.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4444</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;bpatten:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;can you paste the audit findings here in the forum? That&amp;#39;ll help me trace the audit to let you know how we&amp;#39;re detecting it. &lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;Is this what you are asking for?&lt;/p&gt;
&lt;table style="font-family:Verdana;font-size:8pt;" cellpadding="1" cellspacing="0"&gt;

&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;BID&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;34656, 33837&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;CVE&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;CVE-2009-1312, CVE-2009-1310, CVE-2009-1306, 
CVE-2009-1308, CVE-2009-1307, CVE-2009-1309, CVE-2009-0652, CVE-2009-1304, 
CVE-2009-1305, CVE-2009-1311, CVE-2009-1303, CVE-2009-1302&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Multiple vulnerabilities exist in Mozilla products 
(Firefox, Thunderbird, SeaMonkey) that could potentially allow an attacker to 
execute arbitrary code, bypass the same origin policy, read/write local shared 
objects, inject/execute arbitrary HTML or script code, spoof URLs, obtain 
potentially sensitive information, and/or cause denial of service 
conditions.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;How To Fix&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Update to Firefox 3.0.9, Thunderbird 2.0.0.22, 
SeaMonkey 1.1.16, or newest version of these products.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Links&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/seamonkey11.html" target="_blank"&gt;Mozilla SeaMonkey 1.1 - Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox30.html" target="_blank"&gt;Mozilla Firefox 3.0 - Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;a href="http://secunia.com/advisories/34758/" target="_blank"&gt;Secunia Advisory - 
34758&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-15.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-15&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/thunderbird20.html" target="_blank"&gt;Mozilla Thunderbird 2.0 - Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-19.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-19&lt;/a&gt;&lt;br /&gt;&lt;a href="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00724.html" target="_blank"&gt;Fedora Advisory - FEDORA-2009-3893&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-16.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-16&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-17.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-17&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-14.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-14&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-20.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-20&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-21.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-21&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-18.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-18&lt;/a&gt;&lt;br /&gt;&lt;a href="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00682.html" target="_blank"&gt;Fedora Advisory - FEDORA-2009-3875&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-22.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-22&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;Risk&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;
&lt;p&gt;and the second one:&lt;/p&gt;
&lt;table style="font-family:Verdana;font-size:8pt;" cellpadding="1" cellspacing="0"&gt;

&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;BID&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;35391, 35371, 35360, 35372, 35373, 35380, 35370, 
35377, 35388, 35383, 35386&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;CVE&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;CVE-2009-1836, CVE-2009-1841, CVE-2009-1838, 
CVE-2009-1834, CVE-2009-1392, CVE-2009-1839, CVE-2009-1840, CVE-2009-1835, 
CVE-2009-1832, CVE-2009-1837, CVE-2009-1833&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Multiple vulnerabilities exist in Mozilla products 
(Firefox, Thunderbird, SeaMonkey) that could potentially allow an attacker to 
execute arbitrary code, bypass content-policy checks, steal arbitrary cookies, 
intercept SSL-based proxy requests, execute arbitrary JavaScript with chrome 
privileges, access arbitrary local files, and/or spoof location bar 
URLs.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;How To Fix&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Update to Firefox 3.0.11, Thunderbird 2.0.0.22, 
SeaMonkey 1.1.17, or newest version of these products.&lt;br /&gt;&lt;br /&gt;Note: Thunderbird 
and SeaMonkey fixes may not be available. As such, Mozilla suggests disabling 
JavaScript to deter exploitation of certain vulnerabilities.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Links&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-28.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-28&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox30.html" target="_blank"&gt;Mozilla Firefox 3.0 - Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;a href="https://rhn.redhat.com/errata/RHSA-2009-1096.html" target="_blank"&gt;Red Hat 
Advisory - RHSA-2009-1096&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-26.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-26&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/thunderbird20.html" target="_blank"&gt;Mozilla Thunderbird 2.0 - Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-32.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-32&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.redhat.com/archives/fedora-package-announce/2009-June/msg00569.html" target="_blank"&gt;Fedora Advisory - FEDORA-2009-6366&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-29.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-29&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-25.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-25&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-30.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-30&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-27.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-27&lt;/a&gt;&lt;br /&gt;&lt;a href="https://rhn.redhat.com/errata/RHSA-2009-1095.html" target="_blank"&gt;Red Hat 
Advisory - RHSA-2009-1095&lt;/a&gt;&lt;br /&gt;&lt;a href="http://secunia.com/advisories/35331/" target="_blank"&gt;Secunia Advisory - 35331&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/seamonkey11.html" target="_blank"&gt;Mozilla SeaMonkey 1.1 - Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-24.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-24&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-31.html" target="_blank"&gt;Mozilla Advisory - MFSA 2009-31&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.redhat.com/archives/fedora-package-announce/2009-June/msg00640.html" target="_blank"&gt;Fedora Advisory - FEDORA-2009-6411&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;Risk&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;High&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4441.aspx</link><pubDate>Fri, 26 Jun 2009 15:11:17 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4441</guid><dc:creator>bpatten</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4441.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4441</wfw:commentRss><description>&lt;p&gt;can you paste the audit findings here in the forum? That&amp;#39;ll help me trace the audit to let you know how we&amp;#39;re detecting it. &lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Thunderbird vulnerability fix not detected</title><link>http://forums.eeye.com/forums/thread/4436.aspx</link><pubDate>Fri, 26 Jun 2009 00:22:20 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4436</guid><dc:creator>vkundakci</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4436.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4436</wfw:commentRss><description>&lt;p&gt;I run Thunderbird 2.0.0.22 and Thunderbird 3.0b2 and I can&amp;#39;t get rid of the two vulnerabilities which is supposed to be fixed by 2.0.0.22.&lt;/p&gt;
&lt;p&gt;Is the detection scheme not working?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>