Debian Thunderbird vulnerabilities

931 known vulnerabilities affecting debian/thunderbird.

Total CVEs
931
CISA KEV
10
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW90

Vulnerabilities

Page 45 of 47
CVE-2006-2775HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2775 [HIGH] CVE-2006-2775: firefox - Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with th... Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wrong URL. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-3810HIGHCVSS 6.8fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3810 [MEDIUM] CVE-2006-3810: firefox - Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, ... Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2006-3113HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3113 [HIGH] CVE-2006-3113: firefox - Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey be... Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2006-4571HIGHCVSS 10.0fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4571 [CRITICAL] CVE-2006-4571: firefox - Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird befo... Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data. Scope: local sid: resolved (fixed
debian
CVE-2006-3807HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3807 [HIGH] CVE-2006-3807: firefox - Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before... Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2006-1728HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1728 [CRITICAL] CVE-2006-1728: firefox - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 ... Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2006-4566HIGHCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4566 [MEDIUM] CVE-2006-4566: firefox - Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before... Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
debian
CVE-2006-2780HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2780 [CRITICAL] CVE-2006-2780: firefox - Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote... Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-3806HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3806 [HIGH] CVE-2006-3806: firefox - Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.... Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments." Scope: local sid: re
debian
CVE-2006-1735HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1735 [CRITICAL] CVE-2006-1735: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S... Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-2)
debian
CVE-2006-1730HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1730 [CRITICAL] CVE-2006-1730: firefox - Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x... Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2006-2781HIGHCVSS 6.4fixed in thunderbird 1.5.0.4-1 (bookworm)2006
CVE-2006-2781 [MEDIUM] CVE-2006-2781: thunderbird - Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 a... Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters. Scope: local bookworm: resolved (fixed in 1.5.0.4-1) bullseye: resolved (fixed in 1.5.0.4-1) forky: resolved
debian
CVE-2006-3801HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3801 [HIGH] CVE-2006-3801: firefox - Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly ... Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2006-3811HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3811 [HIGH] CVE-2006-3811: firefox - Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1... Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-m
debian
CVE-2006-3803HIGHCVSS 5.1fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3803 [MEDIUM] CVE-2006-3803: firefox - Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 befor... Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object. Scope: local sid: resolved (
debian
CVE-2006-2776HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2776 [HIGH] CVE-2006-2776: firefox - Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 cal... Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-1742MEDIUMCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1742 [MEDIUM] CVE-2006-1742: firefox - The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.... The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption. Scope: local sid: resolved (fixed in 1.
debian
CVE-2006-1731MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1731 [MEDIUM] CVE-2006-1731: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S... Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks. Scope: local sid
debian
CVE-2006-1723MEDIUMCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.2 (sid)2006
CVE-2006-1723 [HIGH] CVE-2006-1723: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk... Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2006-2786MEDIUMCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2786 [LOW] CVE-2006-2786: firefox - HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before ... HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in so
debian