Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 25 of 44
CVE-2019-9811P3HIGHCVSS 8.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-9811 [HIGH] CVE-2019-9811: firefox - As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape b...
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2021-43535P3HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-43535 [HIGH] CVE-2021-43535: firefox - A use-after-free could have occured when an HTTP2 session object was released on...
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2021-23954P3HIGHCVSS 8.8fixed in firefox 85.0-1 (sid)2021
CVE-2021-23954 [HIGH] CVE-2021-23954: firefox - Using the new logical assignment operators in a JavaScript switch statement coul...
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2006-4565P3HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4565 [CRITICAL] CVE-2006-4565: firefox - Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before...
Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
debian
CVE-2017-7805P3HIGHCVSS 7.5fixed in firefox 56.0-1 (sid)2017
CVE-2017-7805 [HIGH] CVE-2017-7805: firefox - During TLS 1.2 exchanges, handshake hashes are generated which point to a messag...
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handsha
debian
CVE-2018-5162P3HIGHCVSS 7.5fixed in thunderbird 1:52.8.0-1 (bookworm)2018
CVE-2018-5162 [HIGH] CVE-2018-5162: thunderbird - Plaintext of decrypted emails can leak through the src attribute of remote image...
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Scope: local
bookworm: resolved (fixed in 1:52.8.0-1)
bullseye: resolved (fixed in 1:52.8.0-1)
forky: resolved (fixed in 1:52.8.0-1)
sid: resolved (fixed in 1:52.8.0-1)
trixie: resolved (fixed in 1:5
debian
CVE-2025-8029P3HIGHCVSS 8.1fixed in firefox 141.0-1 (sid)2025
CVE-2025-8029 [HIGH] CVE-2025-8029: firefox - Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. ...
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Scope: local
sid: resolved (fixed in 141.0-1)
debian
CVE-2021-38498P3HIGHCVSS 7.5fixed in firefox 93.0-1 (sid)2021
CVE-2021-38498 [HIGH] CVE-2021-38498: firefox - During process shutdown, a document could have caused a use-after-free of a lang...
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2023-5728P3HIGHCVSS 7.5fixed in firefox 119.0-1 (sid)2023
CVE-2023-5728 [HIGH] CVE-2023-5728: firefox - During garbage collection extra operations were performed on a object that shoul...
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Scope: local
sid: resolved (fixed in 119.0-1)
debian
CVE-2019-11755P3HIGHCVSS 7.5fixed in thunderbird 1:68.2.1-1 (bookworm)2019
CVE-2019-11755 [HIGH] CVE-2019-11755: thunderbird - A crafted S/MIME message consisting of an inner encryption layer and an outer Si...
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signa
debian
CVE-2022-22737P3HIGHCVSS 7.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22737 [HIGH] CVE-2022-22737: firefox - Constructing audio sinks could have lead to a race condition when playing audio ...
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian
CVE-2024-7652P3HIGHCVSS 7.5fixed in firefox 128.0-1 (sid)2024
CVE-2024-7652 [HIGH] CVE-2024-7652: firefox - An error in the ECMA-262 specification relating to Async Generators could have r...
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2024-9399P3HIGHCVSS 7.5fixed in firefox 131.0-1 (sid)2024
CVE-2024-9399 [HIGH] CVE-2024-9399: firefox - A website configured to initiate a specially crafted WebTransport session could ...
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Scope: local
sid: resolved (fixed in 131.0-1)
debian
CVE-2019-11712P3HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11712 [HIGH] CVE-2019-11712: firefox - POST requests made by NPAPI plugins, such as Flash, that receive a status 308 re...
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2018-5184P3HIGHCVSS 7.5fixed in thunderbird 1:52.8.0-1 (bookworm)2018
CVE-2018-5184 [HIGH] CVE-2018-5184: thunderbird - Using remote content in encrypted messages can lead to the disclosure of plainte...
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Scope: local
bookworm: resolved (fixed in 1:52.8.0-1)
bullseye: resolved (fixed in 1:52.8.0-1)
forky: resolved (fixed in 1:52.8.0-1)
sid: resolved (fixed in 1:52.8.0-1)
trixie: resolved (fixed in 1:52.8.0-1)
debian
CVE-2021-23961P3HIGHCVSS 7.4fixed in firefox 85.0-1 (sid)2021
CVE-2021-23961 [HIGH] CVE-2021-23961: firefox - Further techniques that built on the slipstream research combined with a malicio...
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2023-37208P3HIGHCVSS 7.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37208 [HIGH] CVE-2023-37208: firefox - When opening Diagcab files, Firefox did not warn the user that these files may c...
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2006-2780P3HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2780 [CRITICAL] CVE-2006-2780: firefox - Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote...
Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-1790P3CRITICALCVSS 10.0fixed in firefox 1.5 (sid)2006
CVE-2006-1790 [CRITICAL] CVE-2006-1790: firefox - A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a den...
A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.
Scope: local
sid: resolved (fixed in 1.5)
debian
CVE-2006-3801P3HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3801 [HIGH] CVE-2006-3801: firefox - Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly ...
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian