cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 36 of 44
CVE-2025-1934P4MEDIUMCVSS 6.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1934 [MEDIUM] CVE-2025-1934: firefox - It was possible to interrupt the processing of a RegExp bailout and run addition... It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. Scope: local sid: resolved (fixed in 136.0-1)
debian
CVE-2020-26958P4MEDIUMCVSS 6.1fixed in firefox 83.0-1 (sid)2020
CVE-2020-26958 [MEDIUM] CVE-2020-26958: firefox - Firefox did not block execution of scripts with incorrect MIME types when the re... Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. Scope: local sid: resolved (fixed in 83.0
debian
CVE-2020-26978P4MEDIUMCVSS 6.1fixed in firefox 84.0-1 (sid)2020
CVE-2020-26978 [MEDIUM] CVE-2020-26978: firefox - Using techniques that built on the slipstream research, a malicious webpage coul... Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6. Scope: local sid: resolved (fixed in 84.0-1)
debian
CVE-2024-1551P4MEDIUMCVSS 6.1fixed in firefox 123.0-1 (sid)2024
CVE-2024-1551 [MEDIUM] CVE-2024-1551: firefox - Set-Cookie response headers were being incorrectly honored in multipart HTTP res... Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird <
debian
CVE-2024-1550P4MEDIUMCVSS 6.1fixed in firefox 123.0-1 (sid)2024
CVE-2024-1550 [MEDIUM] CVE-2024-1550: firefox - A malicious website could have used a combination of exiting fullscreen mode and... A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. Scope: loc
debian
CVE-2022-36059P4HIGHCVSS 8.2fixed in thunderbird 1:102.2.1-1 (bookworm)2022
CVE-2022-36059 [HIGH] CVE-2022-36059: node-matrix-js-sdk - matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. I... matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating
debian
CVE-2017-7829P4MEDIUMCVSS 5.3fixed in thunderbird 1:52.5.2-1 (bookworm)2017
CVE-2017-7829 [MEDIUM] CVE-2017-7829: thunderbird - It is possible to spoof the sender's email address and display an arbitrary send... It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2. Scope: local bookworm: resolved (fixed in 1:52.5.2-1) bullseye: resolved (fixed in 1:52.5.2-1) forky:
debian
CVE-2025-0238P4MEDIUMCVSS 5.3fixed in firefox 134.0-1 (sid)2025
CVE-2025-0238 [MEDIUM] CVE-2025-0238: firefox - Assuming a controlled failed memory allocation, an attacker could have caused a ... Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and Thunderbird < 128.6. Scope: local sid: resolved (fixed in 134.0-1)
debian
CVE-2025-5283P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5283 [MEDIUM] CVE-2025-5283: chromium - Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remot... Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.55-1) sid: resolved (fixed in 137.0.7151.55-1) trixie: r
debian
CVE-2026-0886P4MEDIUMCVSS 5.3fixed in firefox 147.0-1 (sid)2026
CVE-2026-0886 [MEDIUM] CVE-2026-0886: firefox - Incorrect boundary conditions in the Graphics component. This vulnerability affe... Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2026-0883P4MEDIUMCVSS 5.3fixed in firefox 147.0-1 (sid)2026
CVE-2026-0883 [MEDIUM] CVE-2026-0883: firefox - Information disclosure in the Networking component. This vulnerability affects F... Information disclosure in the Networking component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2024-10460P4MEDIUMCVSS 5.3fixed in firefox 132.0-1 (sid)2024
CVE-2024-10460 [MEDIUM] CVE-2024-10460: firefox - The origin of an external protocol handler prompt could have been obscured using... The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. Scope: local sid: resolved (fixed in 132.0-1)
debian
CVE-2021-23973P4MEDIUMCVSS 6.5fixed in firefox 86.0-1 (sid)2021
CVE-2021-23973 [MEDIUM] CVE-2021-23973: firefox - When trying to load a cross-origin resource in an audio/video context a decoding... When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. Scope: local sid: resolved (fixed in 86.0-1)
debian
CVE-2020-6795P4MEDIUMCVSS 6.5fixed in thunderbird 1:68.5.0-1 (bookworm)2020
CVE-2020-6795 [MEDIUM] CVE-2020-6795: thunderbird - When processing a message that contains multiple S/MIME signatures, a bug in the... When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploitable crash. This vulnerability affects Thunderbird < 68.5. Scope: local bookworm: resolved (fixed in 1:68.5.0-1) bullseye: resolved (fixed in 1:68.5.0-1) forky: resolved (fixed in 1:68.5.0-1) sid: resolve
debian
CVE-2020-6798P4MEDIUMCVSS 6.1fixed in firefox 73.0-1 (sid)2020
CVE-2020-6798 [MEDIUM] CVE-2020-6798: firefox - If a template tag was used in a select tag, the parser could be confused and all... If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is d
debian
CVE-2019-11739P4MEDIUMCVSS 6.5fixed in thunderbird 1:60.9.0-1 (bookworm)2019
CVE-2019-11739 [MEDIUM] CVE-2019-11739: thunderbird - Encrypted S/MIME parts in a crafted multipart/alternative message can leak plain... Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9. Scope: local bookworm: resolved (fixed in 1:60.9.0-1) bullseye: resolved (fixed in 1:60.9.0-1) forky: resolved (fixed in 1:60.9.0-1) sid: resolved (fixed in 1:60.9.0-
debian
CVE-2022-42929P4MEDIUMCVSS 6.5fixed in firefox 106.0-1 (sid)2022
CVE-2022-42929 [MEDIUM] CVE-2022-42929: firefox - If a website called `window.print()` in a particular way, it could cause a denia... If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4. Scope: local sid: resolved (fixed in 106.0-1)
debian
CVE-2020-15677P4MEDIUMCVSS 6.1fixed in firefox 81.0-1 (sid)2020
CVE-2020-15677 [MEDIUM] CVE-2020-15677: firefox - By exploiting an Open Redirect vulnerability on a website, an attacker could hav... By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3. Scope: local si
debian
CVE-2023-4578P4MEDIUMCVSS 6.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4578 [MEDIUM] CVE-2023-4578: firefox - When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which wo... When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117, Firefox ESR < 1
debian
CVE-2020-15676P4MEDIUMCVSS 6.1fixed in firefox 81.0-1 (sid)2020
CVE-2020-15676 [MEDIUM] CVE-2020-15676: firefox - Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer... Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3. Scope: local sid: resolved (fixed in 81.0-1)
debian
Debian Thunderbird vulnerabilities | cvebase