Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 24 of 44
CVE-2025-10528P3HIGHCVSS 7.3fixed in firefox 143.0-1 (sid)2025
CVE-2025-10528 [HIGH] CVE-2025-10528: firefox - Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canva...
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2018-5125P3HIGHCVSS 8.8fixed in firefox 59.0-1 (sid)2018
CVE-2018-5125 [HIGH] CVE-2018-5125: firefox - Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of the...
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Scope: local
sid: resolved (fixed in 59.0-1)
debian
CVE-2021-38504P3HIGHCVSS 8.8fixed in firefox 94.0-1 (sid)2021
CVE-2021-38504 [HIGH] CVE-2021-38504: firefox - When interacting with an HTML input element's file picker dialog with webkitdire...
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved (fixed in 94.0-1)
debian
CVE-2019-11760P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11760 [HIGH] CVE-2019-11760: firefox - A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling...
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Scope: local
sid: resolved (fixed in 70.0-1)
debian
CVE-2021-29946P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-29946 [HIGH] CVE-2021-29946: firefox - Ports that were written as an integer overflow above the bounds of a 16-bit inte...
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2019-11719P3LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11719 [HIGH] CVE-2019-11719: firefox - When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes,...
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2025-8032P3HIGHCVSS 8.1fixed in firefox 141.0-1 (sid)2025
CVE-2025-8032 [HIGH] CVE-2025-8032: firefox - XSLT document loading did not correctly propagate the source document which bypa...
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Scope: local
sid: resolved (fixed in 141.0-1)
debian
CVE-2023-5724P3HIGHCVSS 7.5fixed in firefox 119.0-1 (sid)2023
CVE-2023-5724 [HIGH] CVE-2023-5724: firefox - Drivers are not always robust to extremely large draw calls and in some cases th...
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Scope: local
sid: resolved (fixed in 119.0-1)
debian
CVE-2024-0743P3HIGHCVSS 7.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0743 [HIGH] CVE-2024-0743: firefox - An unchecked return value in TLS handshake code could have caused a potentially ...
An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2020-12398P3HIGHCVSS 7.5fixed in thunderbird 1:68.9.0-1 (bookworm)2020
CVE-2020-12398 [HIGH] CVE-2020-12398: thunderbird - If Thunderbird is configured to use STARTTLS for an IMAP server, and the server ...
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.
Scope: local
bookworm: resolved (fixed in 1:68.9.0-1)
bullseye: resolved (fixed in 1:68.9.0-1)
f
debian
CVE-2021-29950P3HIGHCVSS 7.5fixed in thunderbird 1:78.9.0-1 (bookworm)2021
CVE-2021-29950 [HIGH] CVE-2021-29950: thunderbird - Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, ...
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
Scope: local
bookworm: resolved (fixed in 1:78.9.0-1)
bullseye: resolved (fixed in 1:78.9.0-1)
forky: resolved (
debian
CVE-2023-4055P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4055 [HIGH] CVE-2023-4055: firefox - When the number of cookies per domain was exceeded in `document.cookie`, the act...
When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0
debian
CVE-2024-1546P3HIGHCVSS 7.5fixed in firefox 123.0-1 (sid)2024
CVE-2024-1546 [HIGH] CVE-2024-1546: firefox - When storing and re-accessing data on a networking channel, the length of buffer...
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Scope: local
sid: resolved (fixed in 123.0-1)
debian
CVE-2022-36319P3HIGHCVSS 7.5fixed in firefox 103.0-1 (sid)2022
CVE-2022-36319 [HIGH] CVE-2022-36319: firefox - When combining CSS properties for overflow and transform, the mouse cursor could...
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
Scope: local
sid: resolved (fixed in 103.0-1)
debian
CVE-2023-4583P3HIGHCVSS 7.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4583 [HIGH] CVE-2023-4583: firefox - When checking if the Browsing Context had been discarded in `HttpBaseChannel`, i...
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
Scope: local
sid: resolved (
debian
CVE-2024-10458P3HIGHCVSS 7.5fixed in firefox 132.0-1 (sid)2024
CVE-2024-10458 [HIGH] CVE-2024-10458: firefox - A permission leak could have occurred from a trusted site to an untrusted site v...
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Scope: local
sid: resolved (fixed in 132.0-1)
debian
CVE-2025-1931P3HIGHCVSS 7.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1931 [HIGH] CVE-2025-1931: firefox - It was possible to cause a use-after-free in the content process side of a WebTr...
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Scope: local
sid: resolved (fixed in 136.0-1)
debian
CVE-2025-3029P3HIGHCVSS 7.3fixed in firefox 137.0-1 (sid)2025
CVE-2025-3029 [HIGH] CVE-2025-3029: firefox - A crafted URL containing specific Unicode characters could have hidden the true ...
A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.
Scope: local
sid: resolved (fixed in 137.0-1)
debian
CVE-2018-12364P3HIGHCVSS 8.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-12364 [HIGH] CVE-2018-12364: firefox - NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, b...
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Fi
debian
CVE-2018-12371P3HIGHCVSS 8.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-12371 [HIGH] CVE-2018-12371: firefox - An integer overflow vulnerability in the Skia library when allocating memory for...
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.
Scope: local
sid: resolved (fixed in 61.0-1)
debian