cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 10 of 44
CVE-2020-15669P3HIGHCVSS 8.8fixed in firefox-esr 68.12.0esr-1 (bookworm)2020
CVE-2020-15669 [HIGH] CVE-2020-15669: firefox-esr - When aborting an operation, such as a fetch, an abort signal may be deleted whil... When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12. Scope: local bookworm: resolved (fixed in 68.12.0
debian
CVE-2024-0750P3HIGHCVSS 8.8fixed in firefox 122.0-1 (sid)2024
CVE-2024-0750 [HIGH] CVE-2024-0750: firefox - A bug in popup notifications delay calculation could have made it possible for a... A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2023-4584P3HIGHCVSS 8.8fixed in firefox 117.0-1 (sid)2023
CVE-2023-4584 [HIGH] CVE-2023-4584: firefox - Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1... Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Th
debian
CVE-2023-6207P3HIGHCVSS 8.8fixed in firefox 120.0-1 (sid)2023
CVE-2023-6207 [HIGH] CVE-2023-6207: firefox - Ownership mismanagement led to a use-after-free in ReadableByteStreams This vuln... Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. Scope: local sid: resolved (fixed in 120.0-1)
debian
CVE-2023-6208P3HIGHCVSS 8.8fixed in firefox 120.0-1 (sid)2023
CVE-2023-6208 [HIGH] CVE-2023-6208: firefox - When using X11, text selected by the page using the Selection API was erroneousl... When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. Scope: local sid: resolved (fixed in 120.0-1)
debian
CVE-2024-11699P3HIGHCVSS 8.8fixed in firefox 133.0-1 (sid)2024
CVE-2024-11699 [HIGH] CVE-2024-11699: firefox - Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 12... Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5. Scope: local sid:
debian
CVE-2023-25729P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25729 [HIGH] CVE-2023-25729: firefox - Permission prompts for opening external schemes were only shown for <code>Conten... Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbir
debian
CVE-2023-3600P3HIGHCVSS 8.8fixed in firefox 115.0.2-1 (sid)2023
CVE-2023-3600 [HIGH] CVE-2023-3600: firefox - During the worker lifecycle, a use-after-free condition could have occurred, whi... During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1. Scope: local sid: resolved (fixed in 115.0.2-1)
debian
CVE-2024-0751P3HIGHCVSS 8.8fixed in firefox 122.0-1 (sid)2024
CVE-2024-0751 [HIGH] CVE-2024-0751: firefox - A malicious devtools extension could have been used to escalate privileges. This... A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2024-7521P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7521 [HIGH] CVE-2024-7521: firefox - Incomplete WebAssembly exception handing could have led to a use-after-free. Thi... Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. Scope: local sid: resolved (fixed in 129.0-1)
debian
CVE-2024-7527P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7527 [HIGH] CVE-2024-7527: firefox - Unexpected marking work at the start of sweeping could have led to a use-after-f... Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. Scope: local sid: resolved (fixed in 129.0-1)
debian
CVE-2024-10467P3HIGHCVSS 8.8fixed in firefox 132.0-1 (sid)2024
CVE-2024-10467 [HIGH] CVE-2024-10467: firefox - Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 12... Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. Scope: local sid:
debian
CVE-2018-12392P3CRITICALCVSS 9.8fixed in firefox 63.0-1 (sid)2018
CVE-2018-12392 [CRITICAL] CVE-2018-12392: firefox - When manipulating user events in nested loops while opening a document through s... When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3. Scope: local sid: resolved (fixed in 63.0-1)
debian
CVE-2024-2612P3HIGHCVSS 8.1fixed in firefox 124.0-1 (sid)2024
CVE-2024-2612 [HIGH] CVE-2024-2612: firefox - If an attacker could find a way to trigger a particular code path in `SafeRefPtr... If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. Scope: local sid: resolved (fixed in 124.0-1)
debian
CVE-2024-3864P3HIGHCVSS 8.1fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3864 [HIGH] CVE-2024-3864: firefox - Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115... Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2025-4091P3HIGHCVSS 8.1fixed in firefox 138.0-1 (sid)2025
CVE-2025-4091 [HIGH] CVE-2025-4091: firefox - Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, a... Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10. S
debian
CVE-2025-4093P3HIGHCVSS 8.1fixed in firefox-esr 128.10.0esr-1~deb12u1 (bookworm)2025
CVE-2025-4093 [HIGH] CVE-2025-4093: firefox-esr - Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug ... Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird < 128.10. Scope: local bookworm: resolved (fixed in 128.10.0esr-1~deb12u1) bullseye: resolve
debian
CVE-2023-4050P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4050 [HIGH] CVE-2023-4050: firefox - In some cases, an untrusted input stream was copied to a stack buffer without ch... In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Scope: local sid: resolved (fixed in 116.0-1)
debian
CVE-2023-5176P3CRITICALCVSS 9.8fixed in firefox 118.0-1 (sid)2023
CVE-2023-5176 [CRITICAL] CVE-2023-5176: firefox - Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 11... Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. Scope: local sid: resolved (fixed i
debian
CVE-2022-31737P3CRITICALCVSS 9.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31737 [CRITICAL] CVE-2022-31737: firefox - A malicious webpage could have caused an out-of-bounds write in WebGL, leading t... A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
Debian Thunderbird vulnerabilities | cvebase