cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 33 of 44
CVE-2022-22748P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22748 [MEDIUM] CVE-2022-22748: firefox - Malicious websites could have confused Firefox into showing the wrong origin whe... Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2022-29916P4MEDIUMCVSS 6.5fixed in firefox 100.0-1 (sid)2022
CVE-2022-29916 [MEDIUM] CVE-2022-29916: firefox - Firefox behaved slightly differently for already known resources when loading CS... Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. Scope: local sid: resolved (fixed in 100.0-1)
debian
CVE-2022-1196P4MEDIUMCVSS 6.5fixed in firefox-esr 91.8.0esr-1 (bookworm)2022
CVE-2022-1196 [MEDIUM] CVE-2022-1196: firefox-esr - After a VR Process is destroyed, a reference to it may have been retained and us... After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8. Scope: local bookworm: resolved (fixed in 91.8.0esr-1) bullseye: resolved (fixed in 91.8.0esr-1~deb11u1) forky: resolved (fixed in 91.8.0esr-1) sid
debian
CVE-2023-25751P4MEDIUMCVSS 6.5fixed in firefox 111.0-1 (sid)2023
CVE-2023-25751 [MEDIUM] CVE-2023-25751: firefox - Sometimes, when invalidating JIT code while following an iterator, the newly gen... Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9. Scope: local sid: resolved (fixed in 111.0-1)
debian
CVE-2022-45416P4MEDIUMCVSS 6.5fixed in firefox 107.0-1 (sid)2022
CVE-2022-45416 [MEDIUM] CVE-2022-45416: firefox - Keyboard events reference strings like "KeyA" that were at fixed, known, and wid... Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107. Scope: local sid: resolved (fixed in 107.0-1)
debian
CVE-2022-46880P4MEDIUMCVSS 6.5fixed in firefox 105.0-1 (sid)2022
CVE-2022-46880 [MEDIUM] CVE-2022-46880: firefox - A missing check related to tex units could have led to a use-after-free and pote... A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird < 102.6. Scop
debian
CVE-2022-22745P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22745 [MEDIUM] CVE-2022-22745: firefox - Securitypolicyviolation events could have leaked cross-origin information for fr... Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2023-1945P4MEDIUMCVSS 6.5fixed in firefox-esr 102.10.0esr-1 (bookworm)2023
CVE-2023-1945 [MEDIUM] CVE-2023-1945: firefox-esr - Unexpected data returned from the Safe Browsing API could have led to memory cor... Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10. Scope: local bookworm: resolved (fixed in 102.10.0esr-1) bullseye: resolved (fixed in 102.10.0esr-1~deb11u1) forky: resolved (fixed in 102.10.0esr-1) sid: resolved (
debian
CVE-2022-29914P4MEDIUMCVSS 6.5fixed in firefox 100.0-1 (sid)2022
CVE-2022-29914 [MEDIUM] CVE-2022-29914: firefox - When reusing existing popups Firefox would have allowed them to cover the fullsc... When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. Scope: local sid: resolved (fixed in 100.0-1)
debian
CVE-2022-31742P4MEDIUMCVSS 6.5fixed in firefox 101.0-1 (sid)2022
CVE-2022-31742 [MEDIUM] CVE-2022-31742: firefox - An attacker could have exploited a timing attack by sending a large number of al... An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope
debian
CVE-2022-31738P4MEDIUMCVSS 6.5fixed in firefox 101.0-1 (sid)2022
CVE-2022-31738 [MEDIUM] CVE-2022-31738: firefox - When exiting fullscreen mode, an iframe could have confused the browser about th... When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2023-0616P4MEDIUMCVSS 6.5fixed in thunderbird 1:102.8.0-1 (bookworm)2023
CVE-2023-0616 [MEDIUM] CVE-2023-0616: thunderbird - If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderb... If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderb
debian
CVE-2022-29913P4MEDIUMCVSS 6.5fixed in thunderbird 1:91.9.0-1 (bookworm)2022
CVE-2022-29913 [MEDIUM] CVE-2022-29913: thunderbird - The parent process would not properly check whether the Speech Synthesis feature... The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9. Scope: local bookworm: resolved (fixed in 1:91.9.0-1) bullseye: resolved (fixed in 1:91.9.0-1~deb11u1) forky: resolved (fixed in 1:91.9.0-1) sid: resolved (fixed in 1:91.9.
debian
CVE-2023-4580P4MEDIUMCVSS 6.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4580 [MEDIUM] CVE-2023-4580: firefox - Push notifications stored on disk in private browsing mode were not being encryp... Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 117.0-1)
debian
CVE-2022-2226P4MEDIUMCVSS 6.5fixed in thunderbird 1:91.11.0-1 (bookworm)2022
CVE-2022-2226 [MEDIUM] CVE-2022-2226: thunderbird - An OpenPGP digital signature includes information about the date when the signat... An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old
debian
CVE-2023-0430P4MEDIUMCVSS 6.5fixed in thunderbird 1:102.7.1+1-1 (bookworm)2023
CVE-2023-0430 [MEDIUM] CVE-2023-0430: thunderbird - Certificate OCSP revocation status was not checked when verifying S/Mime signatu... Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird < 102.7.1. Scope: local bookworm: resolved (fixed in 1:102.7.1+1-1) bullseye: resolved
debian
CVE-2023-0547P4MEDIUMCVSS 6.5fixed in thunderbird 1:102.10.0-1 (bookworm)2023
CVE-2023-0547 [MEDIUM] CVE-2023-0547: thunderbird - OCSP revocation status of recipient certificates was not checked when sending S/... OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10. Scope: local bookworm: resolved (fixed in 1:102.10.0-1) bullseye: resolved (fixed in 1:102.10.0-1~deb1
debian
CVE-2025-8027P4MEDIUMCVSS 6.5fixed in firefox 141.0-1 (sid)2025
CVE-2025-8027 [MEDIUM] CVE-2025-8027: firefox - On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value ... On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2023-28164P4MEDIUMCVSS 6.5fixed in firefox 111.0-1 (sid)2023
CVE-2023-28164 [MEDIUM] CVE-2023-28164: firefox - Dragging a URL from a cross-origin iframe that was removed during the drag could... Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9. Scope: local sid: resolved (fixed in 111.0-1)
debian
CVE-2024-8394P4LOWCVSS 6.5fixed in thunderbird 1:128.2.0esr-1 (forky)2024
CVE-2024-8394 [MEDIUM] CVE-2024-8394: thunderbird - When aborting the verification of an OTR chat session, an attacker could have ca... When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:128.2.0esr-1) sid: resolved (fixed in 1:128.2.0esr-1) trixie: resolved (fixed in 1:128.
debian
Debian Thunderbird vulnerabilities | cvebase