Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 35 of 44
CVE-2021-23998P4MEDIUMCVSS 6.5fixed in firefox 88.0-1 (sid)2021
CVE-2021-23998 [MEDIUM] CVE-2021-23998: firefox - Through complicated navigations with new windows, an HTTP page could have inheri...
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2021-38497P4MEDIUMCVSS 6.5fixed in firefox 93.0-1 (sid)2021
CVE-2021-38497 [MEDIUM] CVE-2021-38497: firefox - Through use of reportValidity() and window.open(), a plain-text validation messa...
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2021-4126P4MEDIUMCVSS 6.5fixed in thunderbird 1:91.4.1-1 (bookworm)2021
CVE-2021-4126 [MEDIUM] CVE-2021-4126: thunderbird - When receiving an OpenPGP/MIME signed email message that contains an additional ...
When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression that the additional contents were also covered by the digital signature. Starting wi
debian
CVE-2023-23601P4MEDIUMCVSS 6.5fixed in firefox 109.0-1 (sid)2023
CVE-2023-23601 [MEDIUM] CVE-2023-23601: firefox - Navigations were being allowed when dragging a URL from a cross-origin iframe in...
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
Scope: local
sid: resolved (fixed in 109.0-1)
debian
CVE-2025-11711P4MEDIUMCVSS 6.5fixed in firefox 144.0-1 (sid)2025
CVE-2025-11711 [MEDIUM] CVE-2025-11711: firefox - There was a way to change the value of JavaScript Object properties that were su...
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Scope: local
sid: resolved (fixed in 144.0-1)
debian
CVE-2024-2609P4MEDIUMCVSS 6.1fixed in firefox 124.0-1 (sid)2024
CVE-2024-2609 [MEDIUM] CVE-2024-2609: firefox - The permission prompt input delay could expire while the window is not in focus....
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2024-5693P4MEDIUMCVSS 6.1fixed in firefox 127.0-1 (sid)2024
CVE-2024-5693 [MEDIUM] CVE-2024-5693: firefox - Offscreen Canvas did not properly track cross-origin tainting, which could be us...
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2023-4049P4MEDIUMCVSS 5.9fixed in firefox 116.0-1 (sid)2023
CVE-2023-4049 [MEDIUM] CVE-2023-4049: firefox - Race conditions in reference counting code were found through code inspection. T...
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2019-11698P4MEDIUMCVSS 5.3fixed in firefox 67.0-2 (sid)2019
CVE-2019-11698 [MEDIUM] CVE-2019-11698: firefox - If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and...
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability
debian
CVE-2025-0510P4HIGHCVSS 7.5fixed in thunderbird 1:128.7.0esr-1~deb12u1 (bookworm)2025
CVE-2025-0510 [HIGH] CVE-2025-0510: thunderbird - Thunderbird displayed an incorrect sender address if the From field of an email ...
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.
Scope: local
bookworm: resolved (fixed in 1:128.7.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.7.0esr-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2018-12373P4MEDIUMCVSS 6.5fixed in thunderbird 1:52.9.0-1 (bookworm)2018
CVE-2018-12373 [MEDIUM] CVE-2018-12373: thunderbird - dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plain...
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
Scope: local
bookworm: resolved (fixed in 1:52.9.0-1)
bullseye: resolved (fixed in 1:52.9.0-1)
forky: resolved (fixed in 1:52.9.0-1)
sid: resolved (fixed in 1:52.9.0-1)
trixie: resolved (fixe
debian
CVE-2021-43545P4MEDIUMCVSS 6.5fixed in firefox 95.0-1 (sid)2021
CVE-2021-43545 [MEDIUM] CVE-2021-43545: firefox - Using the Location API in a loop could have caused severe application hangs and ...
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Scope: local
sid: resolved (fixed in 95.0-1)
debian
CVE-2018-5185P4MEDIUMCVSS 6.5fixed in thunderbird 1:52.8.0-1 (bookworm)2018
CVE-2018-5185 [MEDIUM] CVE-2018-5185: thunderbird - Plaintext of decrypted emails can leak through by user submitting an embedded fo...
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Scope: local
bookworm: resolved (fixed in 1:52.8.0-1)
bullseye: resolved (fixed in 1:52.8.0-1)
forky: resolved (fixed in 1:52.8.0-1)
sid: resolved (fixed in 1:52.8.0-1)
trixie: resolved (fixed in 1:52.8.0-1
debian
CVE-2020-6793P4MEDIUMCVSS 6.5fixed in thunderbird 1:68.5.0-1 (bookworm)2020
CVE-2020-6793 [MEDIUM] CVE-2020-6793: thunderbird - When processing an email message with an ill-formed envelope, Thunderbird could ...
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5.
Scope: local
bookworm: resolved (fixed in 1:68.5.0-1)
bullseye: resolved (fixed in 1:68.5.0-1)
forky: resolved (fixed in 1:68.5.0-1)
sid: resolved (fixed in 1:68.5.0-1)
trixie: resolved (fixed in
debian
CVE-2019-17016P4MEDIUMCVSS 6.1fixed in firefox 72.0-1 (sid)2019
CVE-2019-17016 [MEDIUM] CVE-2019-17016: firefox - When pasting a <style> tag from the clipboard into a rich text editor, the...
When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Scope: local
sid: resolved (fixed in 72.0-1)
debian
CVE-2022-40960P4MEDIUMCVSS 6.5fixed in firefox 105.0-1 (sid)2022
CVE-2022-40960 [MEDIUM] CVE-2022-40960: firefox - Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This c...
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
Scope: local
sid: resolved (fixed in 105.0-1)
debian
CVE-2022-22760P4MEDIUMCVSS 6.5fixed in firefox 97.0-1 (sid)2022
CVE-2022-22760 [MEDIUM] CVE-2022-22760: firefox - When importing resources using Web Workers, error messages would distinguish the...
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
sid: resolved (fixed in 97.0-1)
debian
CVE-2023-32206P4MEDIUMCVSS 6.5fixed in firefox 113.0-1 (sid)2023
CVE-2023-32206 [MEDIUM] CVE-2023-32206: firefox - An out-of-bound read could have led to a crash in the RLBox Expat driver. This v...
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
Scope: local
sid: resolved (fixed in 113.0-1)
debian
CVE-2023-25742P4MEDIUMCVSS 6.5fixed in firefox 110.0-1 (sid)2023
CVE-2023-25742 [MEDIUM] CVE-2023-25742: firefox - When importing a SPKI RSA public key as ECDSA P-256, the key would be handled in...
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2022-22747P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22747 [MEDIUM] CVE-2022-22747: firefox - After accepting an untrusted certificate, handling an empty pkcs7 sequence as pa...
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian