Debian Thunderbird vulnerabilities

931 known vulnerabilities affecting debian/thunderbird.

Total CVEs
931
CISA KEV
10
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW90

Vulnerabilities

Page 36 of 47
CVE-2019-11705CRITICALCVSS 9.8PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11705 [CRITICAL] CVE-2019-11705: thunderbird - A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in... A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1. Scope: local bookworm: resolved (fixed in 1:60.7.1-1) bullseye: resolved (fixed in 1:60.7.1-1) forky: resolved (fixed i
debian
CVE-2019-11708CRITICALCVSS 10.0KEVPoCfixed in firefox 67.0.4-1 (sid)2019
CVE-2019-11708 [CRITICAL] CVE-2019-11708: firefox - Insufficient vetting of parameters passed with the Prompt:Open IPC message betwe... Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firef
debian
CVE-2019-11693CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11693 [CRITICAL] CVE-2019-11693: firefox - The bufferdata function in WebGL is vulnerable to a buffer overflow with specifi... The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox
debian
CVE-2019-9791CRITICALCVSS 9.8PoCfixed in firefox 66.0-1 (sid)2019
CVE-2019-9791 [CRITICAL] CVE-2019-9791: firefox - The type inference system allows the compilation of functions that can cause typ... The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vu
debian
CVE-2019-9790CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9790 [CRITICAL] CVE-2019-9790: firefox - A use-after-free vulnerability can occur when a raw pointer to a DOM element on ... A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2019-11691CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11691 [CRITICAL] CVE-2019-11691: firefox - A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) ... A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-11713CRITICALCVSS 9.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11713 [CRITICAL] CVE-2019-11713: firefox - A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream i... A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2019-9820CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9820 [CRITICAL] CVE-2019-9820: firefox - A use-after-free vulnerability can occur in the chrome event handler when it is ... A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-9819CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9819 [CRITICAL] CVE-2019-9819: firefox - A vulnerability where a JavaScript compartment mismatch can occur while working ... A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-9796CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9796 [CRITICAL] CVE-2019-9796: firefox - A use-after-free vulnerability can occur when the SMIL animation controller inco... A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array. This vulnerabil
debian
CVE-2019-9800CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9800 [CRITICAL] CVE-2019-9800: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR <
debian
CVE-2019-9788CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9788 [CRITICAL] CVE-2019-9788: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox
debian
CVE-2019-9795CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9795 [CRITICAL] CVE-2019-9795: firefox - A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compile... A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2019-11703CRITICALCVSS 9.8PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11703 [CRITICAL] CVE-2019-11703: thunderbird - A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in ... A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1. Scope: local bookworm: resolved (fixed in 1:60.7.1-1) bullseye: resolved (fixed in 1:60.7.1-1) forky: resolved (fixed in 1:6
debian
CVE-2019-11692CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11692 [CRITICAL] CVE-2019-11692: firefox - A use-after-free vulnerability can occur when listeners are removed from the eve... A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-9792CRITICALCVSS 9.8PoCfixed in firefox 66.0-1 (sid)2019
CVE-2019-9792 [CRITICAL] CVE-2019-9792: firefox - The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT ... The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: res
debian
CVE-2019-11704CRITICALCVSS 9.8PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11704 [CRITICAL] CVE-2019-11704: thunderbird - A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in ... A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1. Scope: local bookworm: resolved (fixed in 1:60.7.1-1) bullseye: resolved (fixed in 1:60.7.1-1) forky: resolved (fix
debian
CVE-2019-11709CRITICALCVSS 9.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11709 [CRITICAL] CVE-2019-11709: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: loc
debian
CVE-2019-11706HIGHCVSS 7.5PoCfixed in thunderbird 1:60.7.1-1 (bookworm)2019
CVE-2019-11706 [HIGH] CVE-2019-11706: thunderbird - A flaw in Thunderbird's implementation of iCal causes a type confusion in icalti... A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1. Scope: local bookworm: resolved (fixed in 1:60.7.1-1) bullseye: resolved (fixed in 1:60.7.1-1) forky: resolved (fixed in 1:60.7.1-1) sid: res
debian
CVE-2019-17012HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17012 [HIGH] CVE-2019-17012: firefox - Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed
debian