cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 34 of 44
CVE-2026-3889P4MEDIUMCVSS 6.5fixed in thunderbird 1:140.9.0esr-1~deb12u1 (bookworm)2026
CVE-2026-3889 [MEDIUM] CVE-2026-3889: thunderbird - Spoofing issue in Thunderbird. This vulnerability affects Thunderbird < 149 and ... Spoofing issue in Thunderbird. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9. Scope: local bookworm: resolved (fixed in 1:140.9.0esr-1~deb12u1) bullseye: resolved (fixed in 1:140.9.0esr-1~deb11u1) forky: resolved (fixed in 1:140.9.0esr-1) sid: resolved (fixed in 1:140.9.0esr-1) trixie: resolved (fixed in 1:140.9.0esr-1~deb13u1)
debian
CVE-2024-2610P4MEDIUMCVSS 6.1fixed in firefox 124.0-1 (sid)2024
CVE-2024-2610 [MEDIUM] CVE-2024-2610: firefox - Using a markup injection an attacker could have stolen nonce values. This could ... Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. Scope: local sid: resolved (fixed in 124.0-1)
debian
CVE-2024-9397P4MEDIUMCVSS 6.1fixed in firefox 131.0-1 (sid)2024
CVE-2024-9397 [MEDIUM] CVE-2024-9397: firefox - A missing delay in directory upload UI could have made it possible for an attack... A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131. Scope: local sid: resolved (fixed in 131.0-1)
debian
CVE-2024-3859P4MEDIUMCVSS 5.9fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3859 [MEDIUM] CVE-2024-3859: firefox - On 32-bit versions there were integer-overflows that led to an out-of-bounds-rea... On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2018-18509P4MEDIUMCVSS 5.3fixed in thunderbird 1:60.5.1-1 (bookworm)2018
CVE-2018-18509 [MEDIUM] CVE-2018-18509: thunderbird - A flaw during verification of certain S/MIME signatures causes emails to be show... A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
debian
CVE-2025-0237P4MEDIUMCVSS 5.4fixed in firefox 134.0-1 (sid)2025
CVE-2025-0237 [MEDIUM] CVE-2025-0237: firefox - The WebChannel API, which is used to transport various information across proces... The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. Scope: local sid: resolved (fixed in 134.
debian
CVE-2018-18494P4MEDIUMCVSS 6.5fixed in firefox 64.0-1 (sid)2018
CVE-2018-18494 [MEDIUM] CVE-2018-18494: firefox - A same-origin policy violation allowing the theft of cross-origin URL entries wh... A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. Scope: local sid:
debian
CVE-2020-15652P4MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15652 [MEDIUM] CVE-2020-15652: firefox - By observing the stack trace for JavaScript errors in web workers, it was possib... By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1. Scope: local sid: resolved (fixed in 79.0-1)
debian
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in firefox 88.0-1 (sid)2021
CVE-2021-29945 [MEDIUM] CVE-2021-29945: firefox - The WebAssembly JIT could miscalculate the size of a return type, which could le... The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88. Scope: local sid: resolved (fixed in 88.0-1)
debian
CVE-2019-5785P4MEDIUMCVSS 6.5fixed in firefox 65.0.1-1 (sid)2019
CVE-2019-5785 [MEDIUM] CVE-2019-5785: firefox - Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 ... Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. Scope: local sid: resolved (fixed in 65.0.1-1)
debian
CVE-2006-1723P4MEDIUMCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.2 (sid)2006
CVE-2006-1723 [HIGH] CVE-2006-1723: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk... Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2006-2778P4HIGHCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2778 [MEDIUM] CVE-2006-2778: firefox - The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 a... The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2020-26961P4MEDIUMCVSS 6.5fixed in firefox 83.0-1 (sid)2020
CVE-2020-26961 [MEDIUM] CVE-2020-26961: firefox - When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP r... When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5,
debian
CVE-2018-18499P4MEDIUMCVSS 6.5fixed in firefox 62.0-1 (sid)2018
CVE-2018-18499 [MEDIUM] CVE-2018-18499: firefox - A same-origin policy violation allowing the theft of cross-origin URL entries wh... A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1. Scope: loc
debian
CVE-2020-16042P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16042 [MEDIUM] CVE-2020-16042: chromium - Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote ... Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88
debian
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in firefox 120.0-1 (sid)2023
CVE-2023-6205 [MEDIUM] CVE-2023-6205: firefox - It was possible to cause the use of a MessagePort after it had already been free... It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. Scope: local sid: resolved (fixed in 120.0-1)
debian
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22742 [MEDIUM] CVE-2022-22742: firefox - When inserting text while in edit mode, some characters might have lead to out-o... When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2023-29535P4MEDIUMCVSS 6.5fixed in firefox 112.0-1 (sid)2023
CVE-2023-29535 [MEDIUM] CVE-2023-29535: firefox - Following a Garbage Collector compaction, weak maps may have been accessed befor... Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. Scope: local sid: resolved (fixed in 112.0
debian
CVE-2024-0746P4MEDIUMCVSS 6.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0746 [MEDIUM] CVE-2024-0746: firefox - A Linux user opening the print preview dialog could have caused the browser to c... A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2022-45403P4MEDIUMCVSS 6.5fixed in firefox 107.0-1 (sid)2022
CVE-2022-45403 [MEDIUM] CVE-2022-45403: firefox - Service Workers should not be able to infer information about opaque cross-origi... Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107. Scope: local sid: resolved (fixed
debian
Debian Thunderbird vulnerabilities | cvebase