cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 42 of 44
CVE-2024-4767P4MEDIUMCVSS 4.3fixed in firefox 126.0-1 (sid)2024
CVE-2024-4767 [MEDIUM] CVE-2024-4767: firefox - If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB file... If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Scope: local sid: resolved (fixed in 126.0-1)
debian
CVE-2024-11159P4MEDIUMCVSS 4.3fixed in thunderbird 1:128.4.3esr-1~deb12u1 (bookworm)2024
CVE-2024-11159 [MEDIUM] CVE-2024-11159: thunderbird - Using remote content in OpenPGP encrypted messages can lead to the disclosure of... Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1. Scope: local bookworm: resolved (fixed in 1:128.4.3esr-1~deb12u1) bullseye: resolved (fixed in 1:128.4.3esr-1~deb11u1) forky: resolved (fixed in 1:128.4.3esr-1) sid: resolved (fixed in 1:128.4.3
debian
CVE-2026-0887P4MEDIUMCVSS 4.3fixed in firefox 147.0-1 (sid)2026
CVE-2026-0887 [MEDIUM] CVE-2026-0887: firefox - Clickjacking issue, information disclosure in the PDF Viewer component. This vul... Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2006-3802P4MEDIUMCVSS 5.8fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3802 [MEDIUM] CVE-2006-3802: firefox - Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before... Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2018-5161P4MEDIUMCVSS 4.3fixed in thunderbird 1:52.8.0-1 (bookworm)2018
CVE-2018-5161 [MEDIUM] CVE-2018-5161: thunderbird - Crafted message headers can cause a Thunderbird process to hang on receiving the... Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. Scope: local bookworm: resolved (fixed in 1:52.8.0-1) bullseye: resolved (fixed in 1:52.8.0-1) forky: resolved (fixed in 1:52.8.0-1) sid: resolved (fixed in 1:52.8.0-1) trixie: resolved (fixed in 1:52
debian
CVE-2017-7847P4MEDIUMCVSS 4.3fixed in thunderbird 1:52.5.2-1 (bookworm)2017
CVE-2017-7847 [MEDIUM] CVE-2017-7847: thunderbird - Crafted CSS in an RSS feed can leak and reveal local path strings, which may con... Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2. Scope: local bookworm: resolved (fixed in 1:52.5.2-1) bullseye: resolved (fixed in 1:52.5.2-1) forky: resolved (fixed in 1:52.5.2-1) sid: resolved (fixed in 1:52.5.2-1) trixie: resolved (fixed in 1:52.5.2-1)
debian
CVE-2018-18511P4MEDIUMCVSS 4.3fixed in firefox 65.0.1-1 (sid)2018
CVE-2018-18511 [MEDIUM] CVE-2018-18511: firefox - Cross-origin images can be read from a canvas element in violation of the same-o... Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1. Scope: local sid: resolved (fixed in 65.0.1-1)
debian
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in firefox 77.0-1 (sid)2020
CVE-2020-12399 [MEDIUM] CVE-2020-12399: firefox - NSS has shown timing differences when performing DSA signatures, which was explo... NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. Scope: local sid: resolved (fixed in 77.0-1)
debian
CVE-2022-46877P4MEDIUMCVSS 4.3fixed in firefox 108.0-1 (sid)2022
CVE-2022-46877 [MEDIUM] CVE-2022-46877: firefox - By confusing the browser, the fullscreen notification could have been delayed or... By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2023-50761P4MEDIUMCVSS 4.3fixed in thunderbird 1:115.6.0-1~deb12u1 (bookworm)2023
CVE-2023-50761 [MEDIUM] CVE-2023-50761: thunderbird - The signature of a digitally signed S/MIME email message may optionally specify ... The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent at
debian
CVE-2023-50762P4MEDIUMCVSS 4.3fixed in thunderbird 1:115.6.0-1~deb12u1 (bookworm)2023
CVE-2023-50762 [MEDIUM] CVE-2023-50762: thunderbird - When processing a PGP/MIME payload that contains digitally signed text, the firs... When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to spo
debian
CVE-2021-23992P4MEDIUMCVSS 4.3fixed in thunderbird 1:78.10.0-1 (bookworm)2021
CVE-2021-23992 [MEDIUM] CVE-2021-23992: thunderbird - Thunderbird did not check if the user ID associated with an OpenPGP key has a va... Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to th
debian
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in firefox 122.0-1 (sid)2024
CVE-2024-0749 [MEDIUM] CVE-2024-0749: firefox - A phishing site could have repurposed an `about:` dialog to show phishing conten... A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2025-1935P4MEDIUMCVSS 4.3fixed in firefox 136.0-1 (sid)2025
CVE-2025-1935 [MEDIUM] CVE-2025-1935: firefox - A web page could trick a user into setting that site as the default handler for ... A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. Scope: local sid: resolved (fixed in 136.0-1)
debian
CVE-2025-5266P4MEDIUMCVSS 4.3fixed in firefox 139.0-1 (sid)2025
CVE-2025-5266 [MEDIUM] CVE-2025-5266: firefox - Script elements loading cross-origin resources generated load and error events w... Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Scope: local sid: resolved (fixed in 139.0-1)
debian
CVE-2025-5263P4MEDIUMCVSS 4.3fixed in firefox 139.0-1 (sid)2025
CVE-2025-5263 [MEDIUM] CVE-2025-5263: firefox - Error handling for script execution was incorrectly isolated from web content, w... Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Scope: local sid: resolved (fixed in 139.0-1)
debian
CVE-2006-1942P4LOWCVSS 5.1fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-1942 [MEDIUM] CVE-2006-1942: firefox - Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1... Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma
debian
CVE-2006-4340P4HIGHCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4340 [MEDIUM] CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla... Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE
debian
CVE-2021-23968P4MEDIUMCVSS 4.3fixed in firefox 86.0-1 (sid)2021
CVE-2021-23968 [MEDIUM] CVE-2021-23968: firefox - If Content Security Policy blocked frame navigation, the full destination of a r... If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. Scope: local sid: resolv
debian
CVE-2020-12397P4MEDIUMCVSS 4.3fixed in thunderbird 1:68.8.0-1 (bookworm)2020
CVE-2020-12397 [MEDIUM] CVE-2020-12397: thunderbird - By encoding Unicode whitespace characters within the From email header, an attac... By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0. Scope: local bookworm: resolved (fixed in 1:68.8.0-1) bullseye: resolved (fixed in 1:68.8.0-1) forky: resolved (fixed in 1:68.8.0-1) sid: resolved (fixed in 1:68.8.0-1
debian
Debian Thunderbird vulnerabilities | cvebase