Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 30 of 44
CVE-2025-2830P4MEDIUMCVSS 6.3fixed in thunderbird 1:128.10.0esr-1~deb12u1 (bookworm)2025
CVE-2025-2830 [MEDIUM] CVE-2025-2830: thunderbird - By crafting a malformed file name for an attachment in a multipart message, an a...
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar
debian
CVE-2006-1737P4MEDIUMCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1737 [CRITICAL] CVE-2006-1737: firefox - Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x bef...
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-2)
debian
CVE-2021-29969P4MEDIUMCVSS 5.9fixed in thunderbird 1:78.12.0-1 (bookworm)2021
CVE-2021-29969 [MEDIUM] CVE-2021-29969: thunderbird - If Thunderbird was configured to use STARTTLS for an IMAP connection, and an att...
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders t
debian
CVE-2020-15646P4MEDIUMCVSS 5.9fixed in thunderbird 1:68.10.0-1 (bookworm)2020
CVE-2020-15646 [MEDIUM] CVE-2020-15646: thunderbird - If an attacker intercepts Thunderbird's initial attempt to perform automatic acc...
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
Scope: local
bookworm: resol
debian
CVE-2019-20503P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.149-1 (bookworm)2019
CVE-2019-20503 [MEDIUM] CVE-2019-20503: chromium - usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_in...
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in 80.0.3987.149-1)
debian
CVE-2020-12418P4MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12418 [MEDIUM] CVE-2020-12418: firefox - Manipulating individual parts of a URL object could have caused an out-of-bounds...
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2022-28282P4MEDIUMCVSS 6.5fixed in firefox 99.0-1 (sid)2022
CVE-2022-28282 [MEDIUM] CVE-2022-28282: firefox - By using a link with <code>rel="localization"</code> a use-after-free could have...
By using a link with rel="localization" a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
Scope: local
sid: resolved (fixed in 99.0-1)
debian
CVE-2020-12421P4MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12421 [MEDIUM] CVE-2020-12421: firefox - When performing add-on updates, certificate chains terminating in non-built-in-r...
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
Scope: local
sid: reso
debian
CVE-2021-43542P4MEDIUMCVSS 6.5fixed in firefox 95.0-1 (sid)2021
CVE-2021-43542 [MEDIUM] CVE-2021-43542: firefox - Using XMLHttpRequest, an attacker could have identified installed applications b...
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Scope: local
sid: resolved (fixed in 95.0-1)
debian
CVE-2021-43541P4MEDIUMCVSS 6.5fixed in firefox 95.0-1 (sid)2021
CVE-2021-43541 [MEDIUM] CVE-2021-43541: firefox - When invoking protocol handlers for external protocols, a supplied parameter URL...
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Scope: local
sid: resolved (fixed in 95.0-1)
debian
CVE-2020-26976P4MEDIUMCVSS 6.5fixed in firefox 84.0-1 (sid)2020
CVE-2020-26976 [MEDIUM] CVE-2020-26976: firefox - When a HTTPS pages was embedded in a HTTP page, and there was a service worker r...
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
Scope: local
sid: resolved (fixed in 84.0-1)
debian
CVE-2020-15655P4MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15655 [MEDIUM] CVE-2020-15655: firefox - A redirected HTTP request which is observed or modified through a web extension ...
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Scope: local
sid: resolved (fixed in 79.0-1)
debian
CVE-2020-15664P4MEDIUMCVSS 6.5fixed in firefox 80.0-1 (sid)2020
CVE-2020-15664 [MEDIUM] CVE-2020-15664: firefox - By holding a reference to the eval() function from an about:blank window, a mali...
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thund
debian
CVE-2022-40959P4MEDIUMCVSS 6.5fixed in firefox 105.0-1 (sid)2022
CVE-2022-40959 [MEDIUM] CVE-2022-40959: firefox - During iframe navigation, certain pages did not have their FeaturePolicy fully i...
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
Scope: local
sid: resolved (fixed in 105.0-1)
debian
CVE-2021-43528P4MEDIUMCVSS 6.5fixed in thunderbird 1:91.4.0-1 (bookworm)2021
CVE-2021-43528 [MEDIUM] CVE-2021-43528: thunderbird - Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScr...
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
Scope: local
bookworm: resolved (fixed in 1:91.4.0-1)
debian
CVE-2020-15653P4MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15653 [MEDIUM] CVE-2020-15653: firefox - An iframe sandbox element with the allow-popups flag could be bypassed when usin...
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Scope: local
sid: resolved (fixed in 79.0-1)
debian
CVE-2020-6794P4MEDIUMCVSS 6.5fixed in thunderbird 1:68.5.0-1 (bookworm)2020
CVE-2020-6794 [MEDIUM] CVE-2020-6794: thunderbird - If a user saved passwords before Thunderbird 60 and then later set a master pass...
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure o
debian
CVE-2023-6860P4MEDIUMCVSS 6.5fixed in firefox 121.0-1 (sid)2023
CVE-2023-6860 [MEDIUM] CVE-2023-6860: firefox - The `VideoBridge` allowed any content process to use textures produced by remote...
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2023-6204P4MEDIUMCVSS 6.5fixed in firefox 120.0-1 (sid)2023
CVE-2023-6204 [MEDIUM] CVE-2023-6204: firefox - On some systems—depending on the graphics settings and drivers—it was possible t...
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Scope: local
sid: resolved (fixed in 120.0-1)
debian
CVE-2021-38507P4MEDIUMCVSS 6.5fixed in firefox 94.0-1 (sid)2021
CVE-2021-38507 [MEDIUM] CVE-2021-38507: firefox - The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to ...
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic encryption; a n
debian