{"id":"CVE-2019-10741","details":"K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain valid S/MIME or PGP signatures for arbitrary content to be displayed to a third party. NOTE: the vendor states \"We don't plan to take any action because of this.\"","modified":"2026-08-27T08:40:21.736581Z","published":"2019-04-07T15:29:00.450Z","references":[{"type":"ADVISORY","url":"https://github.com/k9mail/k-9/issues/3925"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thunderbird/thunderbird-android","events":[{"introduced":"a903bd6f81e929bdd486b12e24afe851d06b7dcf"},{"last_affected":"a903bd6f81e929bdd486b12e24afe851d06b7dcf"}],"database_specific":{"cpe":"cpe:2.3:a:k-9_mail_project:k-9_mail:5.600:*:*:*:*:android:*:*","extracted_events":[{"introduced":"5.600"},{"last_affected":"5.600"}],"source":"CPE_STRING"}}],"versions":["5.600"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10741.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}