cbcvebase.

Debian Thunderbird vulnerabilities

864 known vulnerabilities affecting debian/thunderbird.

Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23

Vulnerabilities

Page 9 of 44
CVE-2025-3030P3HIGHCVSS 8.1fixed in firefox 137.0-1 (sid)2025
CVE-2025-3030 [HIGH] CVE-2025-3030: firefox - Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, a... Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. Sco
debian
CVE-2025-5268P3HIGHCVSS 8.1fixed in firefox 139.0-1 (sid)2025
CVE-2025-5268 [HIGH] CVE-2025-5268: firefox - Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, ... Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
debian
CVE-2019-11692P3CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11692 [CRITICAL] CVE-2019-11692: firefox - A use-after-free vulnerability can occur when listeners are removed from the eve... A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2023-5730P3CRITICALCVSS 9.8fixed in firefox 119.0-1 (sid)2023
CVE-2023-5730 [CRITICAL] CVE-2023-5730: firefox - Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 11... Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1. Scope: local sid: resolved (fixed
debian
CVE-2018-5104P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5104 [CRITICAL] CVE-2018-5104: firefox - A use-after-free vulnerability can occur during font face manipulation when a fo... A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. Scope: local sid: resolved (fixed in 58.0-1)
debian
CVE-2018-5102P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5102 [CRITICAL] CVE-2018-5102: firefox - A use-after-free vulnerability can occur when manipulating HTML media elements w... A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. Scope: local sid: resolved (fixed in 58.0-1)
debian
CVE-2022-34470P3CRITICALCVSS 9.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34470 [CRITICAL] CVE-2022-34470: firefox - Session history navigations may have led to a use-after-free and potentially exp... Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2022-31736P3CRITICALCVSS 9.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31736 [CRITICAL] CVE-2022-31736: firefox - A malicious website could have learned the size of a cross-origin resource that ... A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2023-4056P3CRITICALCVSS 9.8fixed in firefox 116.0-1 (sid)2023
CVE-2023-4056 [CRITICAL] CVE-2023-4056: firefox - Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13... Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 1
debian
CVE-2022-46882P3CRITICALCVSS 9.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-46882 [CRITICAL] CVE-2022-46882: firefox - A use-after-free in WebGL extensions could have led to a potentially exploitable... A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6. Scope: local sid: resolved (fixed in 107.0-1)
debian
CVE-2024-9394P3HIGHCVSS 7.5fixed in firefox 131.0-1 (sid)2024
CVE-2024-9394 [HIGH] CVE-2024-9394: firefox - An attacker could, via a specially crafted multipart response, execute arbitrary... An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability
debian
CVE-2024-9393P3HIGHCVSS 7.5fixed in firefox 131.0-1 (sid)2024
CVE-2024-9393 [HIGH] CVE-2024-9393: firefox - An attacker could, via a specially crafted multipart response, execute arbitrary... An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability aff
debian
CVE-2024-9402P3CRITICALCVSS 9.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9402 [CRITICAL] CVE-2024-9402: firefox - Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 12... Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131. Scope: local sid
debian
CVE-2024-8387P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8387 [CRITICAL] CVE-2024-8387: firefox - Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 12... Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2. Scope: local sid: resolved (fixed i
debian
CVE-2021-43529P3CRITICALCVSS 9.8fixed in thunderbird 1:91.3.0-1 (bookworm)2021
CVE-2021-43529 [CRITICAL] CVE-2021-43529: thunderbird - Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow describ... Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures. Scope: local bookworm: resolved (fixed in 1:91.3.0-1
debian
CVE-2019-11759P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11759 [HIGH] CVE-2019-11759: firefox - An attacker could have caused 4 bytes of HMAC output to be written past the end ... An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2018-18493P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-18493 [CRITICAL] CVE-2018-18493: firefox - A buffer overflow can occur in the Skia library during buffer offset calculation... A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. Scope: local sid: resolved (fixed in 64.0-1)
debian
CVE-2023-6861P3HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6861 [HIGH] CVE-2023-6861: firefox - The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflo... The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. Scope: local sid: resolved (fixed in 121.0-1)
debian
CVE-2025-0242P3MEDIUMCVSS 6.5fixed in firefox 134.0-1 (sid)2025
CVE-2025-0242 [MEDIUM] CVE-2025-0242: firefox - Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, ... Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firef
debian
CVE-2020-6822P3HIGHCVSS 8.8fixed in firefox 75.0-1 (sid)2020
CVE-2020-6822 [HIGH] CVE-2020-6822: firefox - On 32-bit builds, an out of bounds write could have occurred when processing an ... On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75. Scope: local sid: resolved (fixed in 75.0-1)
debian
Debian Thunderbird vulnerabilities | cvebase