Debian Thunderbird vulnerabilities

931 known vulnerabilities affecting debian/thunderbird.

Total CVEs
931
CISA KEV
10
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW90

Vulnerabilities

Page 37 of 47
CVE-2019-17011HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17011 [HIGH] CVE-2019-17011: firefox - Under certain conditions, when retrieving a document from a DocShell in the anti... Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-11755HIGHCVSS 7.5fixed in thunderbird 1:68.2.1-1 (bookworm)2019
CVE-2019-11755 [HIGH] CVE-2019-11755: thunderbird - A crafted S/MIME message consisting of an inner encryption layer and an outer Si... A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signa
debian
CVE-2019-11711HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11711 [HIGH] CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ... When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerabil
debian
CVE-2019-11757HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11757 [HIGH] CVE-2019-11757: firefox - When following the value's prototype chain, it was possible to retain a referenc... When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2019-17026HIGHCVSS 8.8KEVPoCfixed in firefox 72.0.1-1 (sid)2019
CVE-2019-17026 [HIGH] CVE-2019-17026: firefox - Incorrect alias information in IonMonkey JIT compiler for setting array elements... Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1. Scope: local sid: resolved (fixed in 72.0.1-1)
debian
CVE-2019-17005HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17005 [HIGH] CVE-2019-17005: firefox - The plain text serializer used a fixed-size array for the number of <ol> element... The plain text serializer used a fixed-size array for the number of elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-17024HIGHCVSS 8.8fixed in firefox 72.0-1 (sid)2019
CVE-2019-17024 [HIGH] CVE-2019-17024: firefox - Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. Scope: local sid: resolved (fixed in 72.0-1)
debian
CVE-2019-11764HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11764 [HIGH] CVE-2019-11764: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: r
debian
CVE-2019-17010HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17010 [HIGH] CVE-2019-17010: firefox - Under certain conditions, when checking the Resist Fingerprinting preference dur... Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-11752HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11752 [HIGH] CVE-2019-11752: firefox - It is possible to delete an IndexedDB key value and subsequently try to extract ... It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2019-11712HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11712 [HIGH] CVE-2019-11712: firefox - POST requests made by NPAPI plugins, such as Flash, that receive a status 308 re... POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2019-9811HIGHCVSS 8.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-9811 [HIGH] CVE-2019-9811: firefox - As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape b... As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2019-11759HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11759 [HIGH] CVE-2019-11759: firefox - An attacker could have caused 4 bytes of HMAC output to be written past the end ... An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2019-17017HIGHCVSS 8.8fixed in firefox 72.0-1 (sid)2019
CVE-2019-17017 [HIGH] CVE-2019-17017: firefox - Due to a missing case handling object types, a type confusion vulnerability coul... Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. Scope: local sid: resolved (fixed in 72.0-1)
debian
CVE-2019-11740HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11740 [HIGH] CVE-2019-11740: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firef
debian
CVE-2019-11746HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11746 [HIGH] CVE-2019-11746: firefox - A use-after-free vulnerability can occur while manipulating video elements if th... A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2019-11760HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11760 [HIGH] CVE-2019-11760: firefox - A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling... A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2019-11707HIGHCVSS 8.8KEVPoCfixed in firefox 67.0.3-1 (sid)2019
CVE-2019-11707 [HIGH] CVE-2019-11707: firefox - A type confusion vulnerability can occur when manipulating JavaScript objects du... A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2. Scope: local sid: resolved (fixed in 67.0.3-1)
debian
CVE-2019-17008HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17008 [HIGH] CVE-2019-17008: firefox - When using nested workers, a use-after-free could occur during worker destructio... When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-11744MEDIUMCVSS 6.1fixed in firefox 69.0-1 (sid)2019
CVE-2019-11744 [MEDIUM] CVE-2019-11744: firefox - Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain lite... Some HTML elements, such as and , can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as it does for ot
debian