cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 43 of 44
CVE-2025-0240P4MEDIUMCVSS 4.0fixed in firefox 134.0-1 (sid)2025
CVE-2025-0240 [MEDIUM] CVE-2025-0240: firefox - Parsing a JavaScript module as JSON could, under some circumstances, cause cross... Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. Scope: local sid: resolved (fixed in 134.0-1)
debian
CVE-2020-6792P4MEDIUMCVSS 4.3fixed in thunderbird 1:68.5.0-1 (bookworm)2020
CVE-2020-6792 [MEDIUM] CVE-2020-6792: thunderbird - When deriving an identifier for an email message, uninitialized memory was used ... When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5. Scope: local bookworm: resolved (fixed in 1:68.5.0-1) bullseye: resolved (fixed in 1:68.5.0-1) forky: resolved (fixed in 1:68.5.0-1) sid: resolved (fixed in 1:68.5.0-1) trixie: resolved (fixed in 1:68
debian
CVE-2021-29957P4MEDIUMCVSS 4.3fixed in thunderbird 1:78.10.2-1 (bookworm)2021
CVE-2021-29957 [MEDIUM] CVE-2021-29957: thunderbird - If a MIME encoded email contains an OpenPGP inline signed or encrypted message p... If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2. Scope: local bookworm: resolved (fixed in 1:78.10.2-1) bullseye: resolved (fixed in 1:78.10.2-1) forky
debian
CVE-2006-0298P4MEDIUMCVSS 5.8fixed in firefox 1.5.dfsg+1.5.0.1-1 (sid)2006
CVE-2006-0298 [MEDIUM] CVE-2006-0298: firefox - The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows... The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.1-1)
debian
CVE-2022-1520P4MEDIUMCVSS 4.3fixed in thunderbird 1:91.9.0-1 (bookworm)2022
CVE-2022-1520 [MEDIUM] CVE-2022-1520: thunderbird - When viewing an email message A, which contains an attached message B, where B i... When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerabil
debian
CVE-2024-3861P4MEDIUMCVSS 4.0fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3861 [MEDIUM] CVE-2024-3861: firefox - If an AlignedBuffer were assigned to itself, the subsequent self-move could resu... If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2006-4568P4LOWCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4568 [MEDIUM] CVE-2006-4568: firefox - Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attacker... Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
debian
CVE-2019-11743P4LOWCVSS 3.7fixed in firefox 69.0-1 (sid)2019
CVE-2019-11743 [LOW] CVE-2019-11743: firefox - Navigation events were not fully adhering to the W3C's "Navigation-Timing Level ... Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affects Firefox < 69,
debian
CVE-2025-0239P4MEDIUMCVSS 4.0fixed in firefox 134.0-1 (sid)2025
CVE-2025-0239 [MEDIUM] CVE-2025-0239: firefox - When using Alt-Svc, ALPN did not properly validate certificates when the origina... When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. Scope: local sid: resolved (fixed in 134.0-1)
debian
CVE-2024-3302P4LOWCVSS 3.7fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3302 [LOW] CVE-2024-3302: firefox - There was no limit to the number of HTTP/2 CONTINUATION frames that would be pro... There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2006-1732P4MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1732 [MEDIUM] CVE-2006-1732: firefox - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and ... Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array. Scope: local sid: resolved (fixed in 1.5.dfsg
debian
CVE-2006-1731P4MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1731 [MEDIUM] CVE-2006-1731: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S... Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks. Scope: local sid
debian
CVE-2025-13015P4LOWCVSS 3.4fixed in firefox 145.0-1 (sid)2025
CVE-2025-13015 [LOW] CVE-2025-13015: firefox - Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR... Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5. Scope: local sid: resolved (fixed in 145.0-1)
debian
CVE-2006-2783P4MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2783 [MEDIUM] CVE-2006-2783: firefox - Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark... Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-3812P4MEDIUMCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3812 [LOW] CVE-2006-3812: firefox - Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before... Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2006-1740P4LOWCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1740 [LOW] CVE-2006-1740: firefox - Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.... Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-2)
debian
CVE-2006-4567P4LOWCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4567 [LOW] CVE-2006-4567: firefox - Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for ... Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arb
debian
CVE-2006-2786P4MEDIUMCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2786 [LOW] CVE-2006-2786: firefox - HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before ... HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in so
debian
CVE-2006-4570P4LOWCVSS 2.6fixed in thunderbird 1.5.0.7-1 (bookworm)2006
CVE-2006-4570 [LOW] CVE-2006-4570: thunderbird - Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images... Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message. Scope: local bookworm: resolved (fixed in 1.5.0.7-1) bullseye: resolved (fixed
debian
CVE-2023-34414P4LOWCVSS 3.1fixed in firefox 114.0-1 (sid)2023
CVE-2023-34414 [LOW] CVE-2023-34414: firefox - The error page for sites with invalid TLS certificates was missing the activatio... The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremely busy at the s
debian
Debian Thunderbird vulnerabilities | cvebase