{
  "modified": "2025-08-09T19:01:26Z",
  "published": "2010-01-29T18:30:01Z",
  "id": "CVE-2010-0464",
  "details": "Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:048"
    },
    {
      "type": "FIX",
      "url": "http://trac.roundcube.net/ticket/1486449"
    },
    {
      "type": "WEB",
      "url": "https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail"
    }
  ]
}
