Debian Thunderbird vulnerabilities
931 known vulnerabilities affecting debian/thunderbird.
Total CVEs
931
CISA KEV
10
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW90
Vulnerabilities
Page 33 of 47
CVE-2020-6805HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6805 [HIGH] CVE-2020-6805: firefox - When removing data about an origin whose tab was recently closed, a use-after-fr...
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid: resolved (fixed in 74.0-1)
debian
CVE-2020-26968HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26968 [HIGH] CVE-2020-26968: firefox - Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Scope: local
sid: resolved (fixed
debian
CVE-2020-6820HIGHCVSS 8.1KEVfixed in firefox 74.0.1-1 (sid)2020
CVE-2020-6820 [HIGH] CVE-2020-6820: firefox - Under certain conditions, when handling a ReadableStream, a race condition can c...
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Scope: local
sid: resolved (fixed in 74.0.1-1)
debian
CVE-2020-12419HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12419 [HIGH] CVE-2020-12419: firefox - When processing callbacks that occurred during window flushing in the parent pro...
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2020-12398HIGHCVSS 7.5fixed in thunderbird 1:68.9.0-1 (bookworm)2020
CVE-2020-12398 [HIGH] CVE-2020-12398: thunderbird - If Thunderbird is configured to use STARTTLS for an IMAP server, and the server ...
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.
Scope: local
bookworm: resolved (fixed in 1:68.9.0-1)
bullseye: resolved (fixed in 1:68.9.0-1)
f
debian
CVE-2020-6800HIGHCVSS 8.8fixed in firefox 73.0-1 (sid)2020
CVE-2020-6800 [HIGH] CVE-2020-6800: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because script
debian
CVE-2020-26959HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26959 [HIGH] CVE-2020-26959: firefox - During browser shutdown, reference decrementing could have occured on a previous...
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Scope: local
sid: resolved (fixed in 83.0-1)
debian
CVE-2020-12406HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12406 [HIGH] CVE-2020-12406: firefox - Mozilla Developer Iain Ireland discovered a missing type check during unboxed ob...
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2020-16044HIGHCVSS 8.8fixed in firefox 84.0.2-1 (sid)2020
CVE-2020-16044 [HIGH] CVE-2020-16044: firefox - Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
Scope: local
sid: resolved (fixed in 84.0.2-1)
debian
CVE-2020-12417HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12417 [HIGH] CVE-2020-12417: firefox - Due to confusion about ValueTags on JavaScript Objects, an object may pass throu...
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2020-15669HIGHCVSS 8.8fixed in firefox-esr 68.12.0esr-1 (bookworm)2020
CVE-2020-15669 [HIGH] CVE-2020-15669: firefox-esr - When aborting an operation, such as a fetch, an abort signal may be deleted whil...
When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.
Scope: local
bookworm: resolved (fixed in 68.12.0
debian
CVE-2020-35113HIGHCVSS 8.8fixed in firefox 84.0-1 (sid)2020
CVE-2020-35113 [HIGH] CVE-2020-35113: firefox - Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Scope: local
sid: resolved (fixed
debian
CVE-2020-26973HIGHCVSS 8.8fixed in firefox 84.0-1 (sid)2020
CVE-2020-26973 [HIGH] CVE-2020-26973: firefox - Certain input to the CSS Sanitizer confused it, resulting in incorrect component...
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Scope: local
sid: resolved (fixed in 84.0-1)
debian
CVE-2020-12387HIGHCVSS 8.1fixed in firefox 76.0-1 (sid)2020
CVE-2020-12387 [HIGH] CVE-2020-12387: firefox - A race condition when running shutdown code for Web Worker led to a use-after-fr...
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Scope: local
sid: resolved (fixed in 76.0-1)
debian
CVE-2020-6811HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6811 [HIGH] CVE-2020-6811: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Fire
debian
CVE-2020-26971HIGHCVSS 8.8fixed in firefox 84.0-1 (sid)2020
CVE-2020-26971 [HIGH] CVE-2020-26971: firefox - Certain blit values provided by the user were not properly constrained leading t...
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Scope: local
sid: resolved (fixed in 84.0-1)
debian
CVE-2020-6821HIGHCVSS 7.5fixed in firefox 75.0-1 (sid)2020
CVE-2020-6821 [HIGH] CVE-2020-6821: firefox - When reading from areas partially or fully outside the source resource with WebG...
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved
debian
CVE-2020-12410HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12410 [HIGH] CVE-2020-12410: firefox - Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixe
debian
CVE-2020-15969HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15969 [HIGH] CVE-2020-15969: chromium - Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fi
debian
CVE-2020-6822HIGHCVSS 8.8fixed in firefox 75.0-1 (sid)2020
CVE-2020-6822 [HIGH] CVE-2020-6822: firefox - On 32-bit builds, an out of bounds write could have occurred when processing an ...
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved (fixed in 75.0-1)
debian