cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 41 of 44
CVE-2021-43538P4MEDIUMCVSS 4.3fixed in firefox 95.0-1 (sid)2021
CVE-2021-43538 [MEDIUM] CVE-2021-43538: firefox - By misusing a race in our notification code, an attacker could have forcefully h... By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. Scope: local sid: resolved (fixed in 95.0-1)
debian
CVE-2021-29956P4MEDIUMCVSS 4.3fixed in thunderbird 1:78.10.2-1 (bookworm)2021
CVE-2021-29956 [MEDIUM] CVE-2021-29956: thunderbird - OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to ve... OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thund
debian
CVE-2023-5721P4MEDIUMCVSS 4.3fixed in firefox 119.0-1 (sid)2023
CVE-2023-5721 [MEDIUM] CVE-2023-5721: firefox - It was possible for certain browser prompts and dialogs to be activated or dismi... It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1. Scope: local sid: resolved (fixed in 119.0-1)
debian
CVE-2022-22743P4MEDIUMCVSS 4.3fixed in firefox 96.0-1 (sid)2022
CVE-2022-22743 [MEDIUM] CVE-2022-22743: firefox - When navigating from inside an iframe while requesting fullscreen access, an att... When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2024-0742P4MEDIUMCVSS 4.3fixed in firefox 122.0-1 (sid)2024
CVE-2024-0742 [MEDIUM] CVE-2024-0742: firefox - It was possible for certain browser prompts and dialogs to be activated or dismi... It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2022-34472P4MEDIUMCVSS 4.3fixed in firefox 102.0-1 (sid)2022
CVE-2022-34472 [MEDIUM] CVE-2022-34472: firefox - If there was a PAC URL set and the server that hosts the PAC was not reachable, ... If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2023-4581P4MEDIUMCVSS 4.3fixed in firefox 117.0-1 (sid)2023
CVE-2023-4581 [MEDIUM] CVE-2023-4581: firefox - Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable... Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 117.0-1)
debian
CVE-2025-6425P4MEDIUMCVSS 4.3fixed in firefox 140.0-1 (sid)2025
CVE-2025-6425 [MEDIUM] CVE-2025-6425: firefox - An attacker who enumerated resources from the WebCompat extension could have obt... An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. Scope: local sid: r
debian
CVE-2026-0818P4MEDIUMCVSS 4.3fixed in thunderbird 1:140.7.1esr-1~deb12u1 (bookworm)2026
CVE-2026-0818 [MEDIUM] CVE-2026-0818: thunderbird - When a user explicitly requested Thunderbird to decrypt an inline OpenPGP messag... When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content re
debian
CVE-2022-3266P4MEDIUMCVSS 5.5fixed in firefox 105.0-1 (sid)2022
CVE-2022-3266 [MEDIUM] CVE-2022-3266: firefox - An out-of-bounds read can occur when decoding H264 video. This results in a pote... An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105. Scope: local sid: resolved (fixed in 105.0-1)
debian
CVE-2018-12367P4MEDIUMCVSS 4.3fixed in firefox 61.0-1 (sid)2018
CVE-2018-12367 [MEDIUM] CVE-2018-12367: firefox - In the previous mitigations for Spectre, the resolution or precision of various ... In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61. Sco
debian
CVE-2021-43546P4MEDIUMCVSS 4.3fixed in firefox 95.0-1 (sid)2021
CVE-2021-43546 [MEDIUM] CVE-2021-43546: firefox - It was possible to recreate previous cursor spoofing attacks against users with ... It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. Scope: local sid: resolved (fixed in 95.0-1)
debian
CVE-2006-0299P4MEDIUMCVSS 6.4fixed in firefox 1.5.dfsg+1.5.0.1-1 (sid)2006
CVE-2006-0299 [MEDIUM] CVE-2006-0299: firefox - The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if run... The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.1-1)
debian
CVE-2021-23969P4MEDIUMCVSS 4.3fixed in firefox 86.0-1 (sid)2021
CVE-2021-23969 [MEDIUM] CVE-2021-23969: firefox - As specified in the W3C Content Security Policy draft, when creating a violation... As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source f
debian
CVE-2021-23953P4MEDIUMCVSS 4.3fixed in firefox 85.0-1 (sid)2021
CVE-2021-23953 [MEDIUM] CVE-2021-23953: firefox - If a user clicked into a specifically crafted PDF, the PDF reader could be confu... If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7. Scope: local sid: resolved (fixed in 85.0-1)
debian
CVE-2022-26383P4MEDIUMCVSS 4.3fixed in firefox 98.0-1 (sid)2022
CVE-2022-26383 [MEDIUM] CVE-2022-26383: firefox - When resizing a popup after requesting fullscreen access, the popup would not di... When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7. Scope: local sid: resolved (fixed in 98.0-1)
debian
CVE-2023-32212P4MEDIUMCVSS 4.3fixed in firefox 113.0-1 (sid)2023
CVE-2023-32212 [MEDIUM] CVE-2023-32212: firefox - An attacker could have positioned a `datalist` element to obscure the address ba... An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. Scope: local sid: resolved (fixed in 113.0-1)
debian
CVE-2023-32205P4MEDIUMCVSS 4.3fixed in firefox 113.0-1 (sid)2023
CVE-2023-32205 [MEDIUM] CVE-2023-32205: firefox - In multiple cases browser prompts could have been obscured by popups controlled ... In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. Scope: local sid: resolved (fixed in 113.0-1)
debian
CVE-2023-29533P4MEDIUMCVSS 4.3fixed in firefox 112.0-1 (sid)2023
CVE-2023-29533 [MEDIUM] CVE-2023-29533: firefox - A website could have obscured the fullscreen notification by using a combination... A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird
debian
CVE-2022-3034P4MEDIUMCVSS 4.3fixed in thunderbird 1:102.2.1-1 (bookworm)2022
CVE-2022-3034 [MEDIUM] CVE-2022-3034: thunderbird - When receiving an HTML email that specified to load an <code>iframe</code> eleme... When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1. Scope: local bookworm: resolved (fixed in 1:102.2.1-1) bullseye: resolved forky: resolved (fixed in 1
debian
Debian Thunderbird vulnerabilities | cvebase