Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 26 of 44
CVE-2006-1045P4LOWCVSS 2.6PoCfixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1045 [LOW] CVE-2006-1045: firefox - The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of rem...
The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.
Sco
debian
CVE-2006-0749P3LOWCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2 (sid)2006
CVE-2006-0749 [CRITICAL] CVE-2006-0749: firefox - nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0....
nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.
Scope: local
sid: r
debian
CVE-2018-5144P3HIGHCVSS 7.3fixed in firefox-esr 52.7.0esr-1 (bookworm)2018
CVE-2018-5144 [HIGH] CVE-2018-5144: firefox-esr - An integer overflow can occur during conversion of text to some Unicode characte...
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
Scope: local
bookworm: resolved (fixed in 52.7.0esr-1)
bullseye: resolved (fixed in 52.7.0esr-1)
forky: resolved (fixed in 52.7.0esr-1)
sid: resolved (fixed in 52.7.0esr-1
debian
CVE-2022-42927P3HIGHCVSS 8.1fixed in firefox 106.0-1 (sid)2022
CVE-2022-42927 [HIGH] CVE-2022-42927: firefox - A same-origin policy violation could have allowed the theft of cross-origin URL ...
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Scope: local
sid: resolved (fixed in 106.0-1)
debian
CVE-2019-17010P3HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17010 [HIGH] CVE-2019-17010: firefox - Under certain conditions, when checking the Resist Fingerprinting preference dur...
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Scope: local
sid: resolved (fixed in 71.0-1)
debian
CVE-2019-17011P3HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17011 [HIGH] CVE-2019-17011: firefox - Under certain conditions, when retrieving a document from a DocShell in the anti...
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Scope: local
sid: resolved (fixed in 71.0-1)
debian
CVE-2020-6821P3HIGHCVSS 7.5fixed in firefox 75.0-1 (sid)2020
CVE-2020-6821 [HIGH] CVE-2020-6821: firefox - When reading from areas partially or fully outside the source resource with WebG...
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved
debian
CVE-2023-1999P3MEDIUMCVSS 5.3fixed in firefox 112.0-1 (sid)2023
CVE-2023-1999 [MEDIUM] CVE-2023-1999: firefox - There exists a use after free/double free in libwebp. An attacker can use the Ap...
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
Scope: local
s
debian
CVE-2018-12379P3LOWCVSS 7.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12379 [HIGH] CVE-2018-12379: firefox - When the Mozilla Updater opens a MAR format file which contains a very long item...
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbi
debian
CVE-2023-4048P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4048 [HIGH] CVE-2023-4048: firefox - An out-of-bounds read could have led to an exploitable crash when parsing HTML w...
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2006-4571P3HIGHCVSS 10.0fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4571 [CRITICAL] CVE-2006-4571: firefox - Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird befo...
Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data.
Scope: local
sid: resolved (fixed
debian
CVE-2025-1938P3MEDIUMCVSS 6.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1938 [MEDIUM] CVE-2025-1938: firefox - Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, a...
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
S
debian
CVE-2019-11729P4LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11729 [HIGH] CVE-2019-11729: firefox - Empty or malformed p256-ECDH public keys may trigger a segmentation fault due va...
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2021-23981P3HIGHCVSS 8.1fixed in firefox 87.0-1 (sid)2021
CVE-2021-23981 [HIGH] CVE-2021-23981: firefox - A texture upload of a Pixel Buffer Object could have confused the WebGL code to ...
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
Scope: local
sid: resolved (fixed in 87.0-1)
debian
CVE-2018-18513P4HIGHCVSS 7.5fixed in thunderbird 1:60.5.0-1 (bookworm)2018
CVE-2018-18513 [HIGH] CVE-2018-18513: thunderbird - A crash can occur when processing a crafted S/MIME message or an XPI package con...
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again. This vulnerability affects Thunderbird < 60.5.
Scope: local
bookworm: resolved (fixed in 1:60.5.0-1)
bullseye: r
debian
CVE-2021-29949P4HIGHCVSS 7.8fixed in thunderbird 1:78.10.0-1 (bookworm)2021
CVE-2021-29949 [HIGH] CVE-2021-29949: thunderbird - When loading the shared library that provides the OTR protocol implementation, T...
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search
debian
CVE-2006-1727P4MEDIUMCVSS 7.6fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1727 [HIGH] CVE-2006-1727: firefox - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 ...
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2025-1933P3HIGHCVSS 7.6fixed in firefox 136.0-1 (sid)2025
CVE-2025-1933 [HIGH] CVE-2025-1933: firefox - On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bi...
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Scope: local
sid: resolved (fixed in 136.0-1)
debian
CVE-2006-3805P3HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3805 [HIGH] CVE-2006-3805: firefox - The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5....
The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2024-0741P3MEDIUMCVSS 6.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0741 [MEDIUM] CVE-2024-0741: firefox - An out of bounds write in ANGLE could have allowed an attacker to corrupt memory...
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian