Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-12269.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "2.0.11" } ] } ]