Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 2 of 44
CVE-2019-11703P2CRITICALCVSS 9.8PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11703 [CRITICAL] CVE-2019-11703: thunderbird - A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in ...
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Scope: local
bookworm: resolved (fixed in 1:60.7.1-1)
bullseye: resolved (fixed in 1:60.7.1-1)
forky: resolved (fixed in 1:6
debian
CVE-2019-11704P2CRITICALCVSS 9.8PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11704 [CRITICAL] CVE-2019-11704: thunderbird - A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in ...
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Scope: local
bookworm: resolved (fixed in 1:60.7.1-1)
bullseye: resolved (fixed in 1:60.7.1-1)
forky: resolved (fix
debian
CVE-2019-11705P2CRITICALCVSS 9.8PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11705 [CRITICAL] CVE-2019-11705: thunderbird - A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in...
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Scope: local
bookworm: resolved (fixed in 1:60.7.1-1)
bullseye: resolved (fixed in 1:60.7.1-1)
forky: resolved (fixed i
debian
CVE-2019-9792P2CRITICALCVSS 9.8PoCfixed in firefox 66.0-1 (sid)2019
CVE-2019-9792 [CRITICAL] CVE-2019-9792: firefox - The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT ...
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Scope: local
sid: res
debian
CVE-2019-11706P3HIGHCVSS 7.5PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11706 [HIGH] CVE-2019-11706: thunderbird - A flaw in Thunderbird's implementation of iCal causes a type confusion in icalti...
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.
Scope: local
bookworm: resolved (fixed in 1:60.7.1-1)
bullseye: resolved (fixed in 1:60.7.1-1)
forky: resolved (fixed in 1:60.7.1-1)
sid: res
debian
CVE-2006-0295P3MEDIUMCVSS 5.1PoCfixed in firefox 1.5.dfsg+1.5.0.1-1 (sid)2006
CVE-2006-0295 [MEDIUM] CVE-2006-0295: firefox - Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMo...
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.1-1)
debian
CVE-2023-6856P2HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6856 [HIGH] CVE-2023-6856: firefox - The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overfl...
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2019-9816P3MEDIUMCVSS 5.9PoCfixed in firefox 67.0-2 (sid)2019
CVE-2019-9816 [MEDIUM] CVE-2019-9816: firefox - A possible vulnerability exists where type confusion can occur when manipulating...
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Fir
debian
CVE-2022-2200P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-2200 [HIGH] CVE-2022-2200: firefox - If an object prototype was corrupted by an attacker, they would have been able t...
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
sid: resolved (fixed in 102.0-1)
debian
CVE-2006-4253P3MEDIUMCVSS 7.6PoCfixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4253 [HIGH] CVE-2006-4253: firefox - Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote a...
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectl
debian
CVE-2006-0884P3CRITICALCVSS 9.3PoCfixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-0884 [CRITICAL] CVE-2006-0884: firefox - The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 a...
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
Scope: local
sid: resolv
debian
CVE-2025-4918P3CRITICALCVSS 9.8fixed in firefox 138.0.4-1 (sid)2025
CVE-2025-4918 [CRITICAL] CVE-2025-4918: firefox - An attacker was able to perform an out-of-bounds read or write on a JavaScript `...
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
Scope: local
sid: resolved (fixed in 138.0.4-1)
debian
CVE-2018-18505P3CRITICALCVSS 10.0fixed in firefox 65.0-1 (sid)2018
CVE-2018-18505 [CRITICAL] CVE-2018-18505: firefox - An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-...
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. Th
debian
CVE-2024-8381P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8381 [CRITICAL] CVE-2024-8381: firefox - A potentially exploitable type confusion could be triggered when looking up a pr...
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Scope: local
sid: resolved (fixed in 130.0-1)
debian
CVE-2021-38503P3CRITICALCVSS 10.0fixed in firefox 94.0-1 (sid)2021
CVE-2021-38503 [CRITICAL] CVE-2021-38503: firefox - The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowin...
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved (fixed in 94.0-1)
debian
CVE-2026-4688P3CRITICALCVSS 10.0fixed in firefox 149.0-1 (sid)2026
CVE-2026-4688 [CRITICAL] CVE-2026-4688: firefox - Sandbox escape due to use-after-free in the Disability Access APIs component. Th...
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-2768P3CRITICALCVSS 10.0fixed in firefox 148.0-1 (sid)2026
CVE-2026-2768 [CRITICAL] CVE-2026-2768: firefox - Sandbox escape in the Storage: IndexedDB component. This vulnerability affects F...
Sandbox escape in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-4692P3CRITICALCVSS 10.0fixed in firefox 149.0-1 (sid)2026
CVE-2026-4692 [CRITICAL] CVE-2026-4692: firefox - Sandbox escape in the Responsive Design Mode component. This vulnerability affec...
Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-2776P3CRITICALCVSS 10.0fixed in firefox 148.0-1 (sid)2026
CVE-2026-2776 [CRITICAL] CVE-2026-2776: firefox - Sandbox escape due to incorrect boundary conditions in the Telemetry component i...
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2761P3CRITICALCVSS 10.0fixed in firefox 148.0-1 (sid)2026
CVE-2026-2761 [CRITICAL] CVE-2026-2761: firefox - Sandbox escape in the Graphics: WebRender component. This vulnerability affects ...
Sandbox escape in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian