cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 40 of 44
CVE-2019-9817P4MEDIUMCVSS 5.3fixed in firefox 67.0-2 (sid)2019
CVE-2019-9817 [MEDIUM] CVE-2019-9817: firefox - Images from a different domain can be read using a canvas object in some circums... Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2006-3810P4HIGHCVSS 6.8fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3810 [MEDIUM] CVE-2006-3810: firefox - Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, ... Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2018-5170P4MEDIUMCVSS 4.3fixed in thunderbird 1:52.8.0-1 (bookworm)2018
CVE-2018-5170 [MEDIUM] CVE-2018-5170: thunderbird - It is possible to spoof the filename of an attachment and display an arbitrary a... It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. Scope: local bookworm: resolved (fixed in 1:52.8.0-1) bullseye: resolved (fixed in 1:52.8.0-1)
debian
CVE-2024-5691P4MEDIUMCVSS 4.7fixed in firefox 127.0-1 (sid)2024
CVE-2024-5691 [MEDIUM] CVE-2024-5691: firefox - By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe coul... By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. Scope: local sid: resolved (fixed in 127.0-1)
debian
CVE-2025-5264P4MEDIUMCVSS 4.8fixed in firefox 139.0-1 (sid)2025
CVE-2025-5264 [MEDIUM] CVE-2025-5264: firefox - Due to insufficient escaping of the newline character in the “Copy as cURL” feat... Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Scope: local sid: resolved (fi
debian
CVE-2024-6601P4MEDIUMCVSS 4.7fixed in firefox 128.0-1 (sid)2024
CVE-2024-6601 [MEDIUM] CVE-2024-6601: firefox - A race condition could lead to a cross-origin container obtaining permissions of... A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2006-1742P4MEDIUMCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1742 [MEDIUM] CVE-2006-1742: firefox - The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.... The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption. Scope: local sid: resolved (fixed in 1.
debian
CVE-2024-1548P4MEDIUMCVSS 4.3fixed in firefox 123.0-1 (sid)2024
CVE-2024-1548 [MEDIUM] CVE-2024-1548: firefox - A website could have obscured the fullscreen notification by using a dropdown se... A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. Scope: local sid: resolved (fixed in 123.0-1)
debian
CVE-2023-5725P4MEDIUMCVSS 4.3fixed in firefox 119.0-1 (sid)2023
CVE-2023-5725 [MEDIUM] CVE-2023-5725: firefox - A malicious installed WebExtension could open arbitrary URLs, which under the ri... A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1. Scope: local sid: resolved (fixed in 119.0-1)
debian
CVE-2024-5690P4MEDIUMCVSS 4.3fixed in firefox 127.0-1 (sid)2024
CVE-2024-5690 [MEDIUM] CVE-2024-5690: firefox - By monitoring the time certain operations take, an attacker could have guessed w... By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. Scope: local sid: resolved (fixed in 127.0-1)
debian
CVE-2024-11692P4MEDIUMCVSS 4.3fixed in firefox 133.0-1 (sid)2024
CVE-2024-11692 [MEDIUM] CVE-2024-11692: firefox - An attacker could cause a select dropdown to be shown over another tab; this cou... An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5. Scope: local sid: resolved (fixed in 133.0-1)
debian
CVE-2006-1738P4MEDIUMCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1738 [MEDIUM] CVE-2006-1738: firefox - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and ... Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-2)
debian
CVE-2006-4566P4HIGHCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4566 [MEDIUM] CVE-2006-4566: firefox - Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before... Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
debian
CVE-2006-1741P4MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1741 [MEDIUM] CVE-2006-1741: firefox - Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.... Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__
debian
CVE-2020-16012P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16012 [MEDIUM] CVE-2020-16012: chromium - Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280... Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: res
debian
CVE-2018-12374P4MEDIUMCVSS 4.3fixed in thunderbird 1:52.9.0-1 (bookworm)2018
CVE-2018-12374 [MEDIUM] CVE-2018-12374: thunderbird - Plaintext of decrypted emails can leak through by user submitting an embedded fo... Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9. Scope: local bookworm: resolved (fixed in 1:52.9.0-1) bullseye: resolved (fixed in 1:52.9.0-1) forky: resolved (fixed in 1:52.9.0-1) sid: resolved (fixed in 1:52.9.0-1) trixie: resolv
debian
CVE-2021-38508P4MEDIUMCVSS 4.3fixed in firefox 94.0-1 (sid)2021
CVE-2021-38508 [MEDIUM] CVE-2021-38508: firefox - By displaying a form validity message in the correct location at the same time a... By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. Scope: local sid: res
debian
CVE-2021-38506P4MEDIUMCVSS 4.3fixed in firefox 94.0-1 (sid)2021
CVE-2021-38506 [MEDIUM] CVE-2021-38506: firefox - Through a series of navigations, Firefox could have entered fullscreen mode with... Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. Scope: local sid: resolved (fixed in 94.0-1)
debian
CVE-2020-26953P4MEDIUMCVSS 4.3fixed in firefox 83.0-1 (sid)2020
CVE-2020-26953 [MEDIUM] CVE-2020-26953: firefox - It was possible to cause the browser to enter fullscreen mode without displaying... It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. Scope: local sid: resolved (fixed in 83.0-1)
debian
CVE-2020-35111P4MEDIUMCVSS 4.3fixed in firefox 84.0-1 (sid)2020
CVE-2020-35111 [MEDIUM] CVE-2020-35111: firefox - When an extension with the proxy permission registered to receive <all_urls>, th... When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6. Scope: local sid: r
debian
Debian Thunderbird vulnerabilities | cvebase