Debian Thunderbird vulnerabilities
931 known vulnerabilities affecting debian/thunderbird.
Total CVEs
931
CISA KEV
10
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW90
Vulnerabilities
Page 23 of 47
CVE-2022-46871HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46871 [HIGH] CVE-2022-46871: firefox - An out of date library (libusrsctp) contained vulnerabilities that could potenti...
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
Scope: local
sid: resolved (fixed in 108.0-1)
debian
CVE-2022-22740HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22740 [HIGH] CVE-2022-22740: firefox - Certain network request objects were freed too early when releasing a network re...
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian
CVE-2022-24713HIGHCVSS 7.5fixed in firefox 99.0-1 (sid)2022
CVE-2022-24713 [HIGH] CVE-2022-24713: firefox - regex is an implementation of regular expressions for the Rust language. The reg...
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of t
debian
CVE-2022-42928HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-42928 [HIGH] CVE-2022-42928: firefox - Certain types of allocations were missing annotations that, if the Garbage Colle...
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Scope: local
sid: resolved (fixed in 106.0-1)
debian
CVE-2022-42927HIGHCVSS 8.1fixed in firefox 106.0-1 (sid)2022
CVE-2022-42927 [HIGH] CVE-2022-42927: firefox - A same-origin policy violation could have allowed the theft of cross-origin URL ...
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Scope: local
sid: resolved (fixed in 106.0-1)
debian
CVE-2022-2505HIGHCVSS 8.8fixed in firefox 103.0-1 (sid)2022
CVE-2022-2505 [HIGH] CVE-2022-2505: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres...
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
Scope: local
sid: resolv
debian
CVE-2022-26381HIGHCVSS 8.8fixed in firefox 98.0-1 (sid)2022
CVE-2022-26381 [HIGH] CVE-2022-26381: firefox - An attacker could have caused a use-after-free by forcing a text reflow in an SV...
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
Scope: local
sid: resolved (fixed in 98.0-1)
debian
CVE-2022-38476HIGHCVSS 7.5fixed in firefox-esr 102.2.0esr-1 (bookworm)2022
CVE-2022-38476 [HIGH] CVE-2022-38476: firefox-esr - A data race could occur in the <code>PK11_ChangePW</code> function, potentially ...
A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
Scope: local
bookworm: resolved (fixed in 102.2.0esr-1)
bullseye: resolved
forky: resolved (fixed
debian
CVE-2022-36319HIGHCVSS 7.5fixed in firefox 103.0-1 (sid)2022
CVE-2022-36319 [HIGH] CVE-2022-36319: firefox - When combining CSS properties for overflow and transform, the mouse cursor could...
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
Scope: local
sid: resolved (fixed in 103.0-1)
debian
CVE-2022-36059HIGHCVSS 8.2fixed in thunderbird 1:102.2.1-1 (bookworm)2022
CVE-2022-36059 [HIGH] CVE-2022-36059: node-matrix-js-sdk - matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. I...
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating
debian
CVE-2022-46878HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46878 [HIGH] CVE-2022-46878: firefox - Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fu...
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6
debian
CVE-2022-45421HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-45421 [HIGH] CVE-2022-45421: firefox - Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety b...
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Scope: l
debian
CVE-2022-34484HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34484 [HIGH] CVE-2022-34484: firefox - The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbi...
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
debian
CVE-2022-29909HIGHCVSS 8.8fixed in firefox 100.0-1 (sid)2022
CVE-2022-29909 [HIGH] CVE-2022-29909: firefox - Documents in deeply-nested cross-origin browsing contexts could have obtained pe...
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
Scope: local
sid: resolved (fixed in 100.0-1)
debian
CVE-2022-45414HIGHCVSS 8.1fixed in thunderbird 1:102.5.1-1 (bookworm)2022
CVE-2022-45414 [HIGH] CVE-2022-45414: thunderbird - If a Thunderbird user quoted from an HTML email, for example by replying to the ...
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown
debian
CVE-2022-1802HIGHCVSS 8.8Exploitedfixed in firefox 100.0.2-1 (sid)2022
CVE-2022-1802 [HIGH] CVE-2022-1802: firefox - If an attacker was able to corrupt the methods of an Array object in JavaScript ...
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
Scope: local
sid: resolved (fixed in 100.
debian
CVE-2022-38477HIGHCVSS 8.8fixed in firefox 104.0-1 (sid)2022
CVE-2022-38477 [HIGH] CVE-2022-38477: firefox - Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safe...
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird < 102.2, and Fir
debian
CVE-2022-31741HIGHCVSS 8.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31741 [HIGH] CVE-2022-31741: firefox - A crafted CMS message could have been processed incorrectly, leading to an inval...
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Scope: local
sid: resolved (fixed in 101.0-1)
debian
CVE-2022-22763HIGHCVSS 8.8fixed in firefox-esr 91.6.0esr-1 (bookworm)2022
CVE-2022-22763 [HIGH] CVE-2022-22763: firefox-esr - When a worker is shutdown, it was possible to cause script to run late in the li...
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
bookworm: resolved (fixed in 91.6.0esr-1)
bullseye: resolved (fixed in 91.6.0esr-1~deb11u1)
forky: resolved (fixed in 91.6.0esr
debian
CVE-2022-34468HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34468 [HIGH] CVE-2022-34468: firefox - An iframe that was not permitted to run scripts could do so if the user clicked ...
An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
sid: resolved (fixed in 102.0-1)
debian