cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 22 of 44
CVE-2020-12419P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12419 [HIGH] CVE-2020-12419: firefox - When processing callbacks that occurred during window flushing in the parent pro... When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6514 [MEDIUM] CVE-2020-6514: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 al... Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixe
debian
CVE-2019-17005P3HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17005 [HIGH] CVE-2019-17005: firefox - The plain text serializer used a fixed-size array for the number of <ol> element... The plain text serializer used a fixed-size array for the number of elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2021-29980P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29980 [HIGH] CVE-2021-29980: firefox - Uninitialized memory in a canvas object could have caused an incorrect free() le... Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91. Scope: local sid: resolved (fixed in 91.0-1)
debian
CVE-2022-22738P3HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22738 [HIGH] CVE-2022-22738: firefox - Applying a CSS filter effect could have accessed out of bounds memory. This coul... Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2022-34468P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34468 [HIGH] CVE-2022-34468: firefox - An iframe that was not permitted to run scripts could do so if the user clicked ... An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2022-46871P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46871 [HIGH] CVE-2022-46871: firefox - An out of date library (libusrsctp) contained vulnerabilities that could potenti... An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2022-29909P3HIGHCVSS 8.8fixed in firefox 100.0-1 (sid)2022
CVE-2022-29909 [HIGH] CVE-2022-29909: firefox - Documents in deeply-nested cross-origin browsing contexts could have obtained pe... Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. Scope: local sid: resolved (fixed in 100.0-1)
debian
CVE-2022-45412P3HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-45412 [HIGH] CVE-2022-45412: firefox - When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error m... When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and F
debian
CVE-2022-34481P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34481 [HIGH] CVE-2022-34481: firefox - In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer over... In the nsTArray_Impl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2023-32213P3HIGHCVSS 8.8fixed in firefox 113.0-1 (sid)2023
CVE-2023-32213 [HIGH] CVE-2023-32213: firefox - When reading a file, an uninitialized value could have been used as read limit. ... When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. Scope: local sid: resolved (fixed in 113.0-1)
debian
CVE-2022-46881P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-46881 [HIGH] CVE-2022-46881: firefox - An optimization in WebGL was incorrect in some cases, and could have led to memo... An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR < 102.6, and Th
debian
CVE-2022-31741P3HIGHCVSS 8.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31741 [HIGH] CVE-2022-31741: firefox - A crafted CMS message could have been processed incorrectly, leading to an inval... A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2018-5183P3CRITICALCVSS 9.8fixed in firefox-esr 52.8.0esr-1 (bookworm)2018
CVE-2018-5183 [CRITICAL] CVE-2018-5183: firefox-esr - Mozilla developers backported selected changes in the Skia library. These change... Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8. Scope: local bookworm: resolved (fixed in 52.8.0esr-1) bullseye: resolved (fixed in
debian
CVE-2018-5145P3CRITICALCVSS 9.8fixed in firefox-esr 52.7.0esr-1 (bookworm)2018
CVE-2018-5145 [CRITICAL] CVE-2018-5145: firefox-esr - Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence... Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. Scope: local bookworm: resolved (fixed in 52.7.0esr-1) bullseye: resolved (fixed in 52.7.0
debian
CVE-2017-7810P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7810 [CRITICAL] CVE-2017-7810: firefox - Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of the... Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: local sid: resolved (fixed in 56.0-1)
debian
CVE-2022-3033P3HIGHCVSS 8.1fixed in thunderbird 1:102.2.1-1 (bookworm)2022
CVE-2022-3033 [HIGH] CVE-2022-3033: thunderbird - If a Thunderbird user replied to a crafted HTML email containing a <code>meta</c... If a Thunderbird user replied to a crafted HTML email containing a meta tag, with the meta tag having the http-equiv="refresh" attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attributes in the
debian
CVE-2025-8030P3HIGHCVSS 8.1fixed in firefox 141.0-1 (sid)2025
CVE-2025-8030 [HIGH] CVE-2025-8030: firefox - Insufficient escaping in the “Copy as cURL” feature could potentially be used to... Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2026-0878P3HIGHCVSS 8.0fixed in firefox 147.0-1 (sid)2026
CVE-2026-0878 [HIGH] CVE-2026-0878: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL... Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2024-3857P3HIGHCVSS 7.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3857 [HIGH] CVE-2024-3857: firefox - The JIT created incorrect code for arguments in certain cases. This led to poten... The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
Debian Thunderbird vulnerabilities | cvebase