Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 101 of 101
CVE-2024-2616P4LOWCVSS 2.7fixed in 115.9.0≥ unspecified, < 115.92024-03-19
CVE-2024-2616 [LOW] CWE-787 CVE-2024-2616: To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash i
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.
nvdosv
CVE-2004-1449P4LOWCVSS 2.6v0.1v0.2+4 more2004-12-31
CVE-2004-1449 [LOW] CVE-2004-1449: Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determ
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.
nvd
CVE-2021-29948P4LOWCVSS 2.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-29948 [LOW] CWE-362 CVE-2021-29948: Signatures are written to disk before and read during verification, which might be subject to a race
Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.
nvdosv
CVE-2006-4569P4LOWCVSS 2.6≥ 0, < 1.5.0.7-12006-09-15
CVE-2006-4569 [LOW] CVE-2006-4569: The popup blocker in Mozilla Firefox before 1
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
osv
CVE-2005-2353P4LOWCVSS 2.1v1.5.0.92005-08-05
CVE-2005-2353 [LOW] CVE-2005-2353: run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arb
run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
nvdosv
CVE-2012-1945P4LOWCVSS 2.9v5.0v6.0+14 more2012-06-05
CVE-2012-1945 [LOW] CWE-200 CVE-2012-1945: Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thun
Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (
nvd
CVE-2014-1595P4LOWCVSS 2.1≤ 31.22014-12-11
CVE-2014-1595 [LOW] CWE-199 CVE-2014-1595: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
nvd
CVE-2005-0142P4LOWCVSS 2.1v0.6v0.7+1 more2005-05-02
CVE-2005-0142 [LOW] CVE-2005-0142: Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save tempor
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
nvd
CVE-2019-18511CRITICALCVSS 9.8≥ 0, < 1:60.7.0+build1-0ubuntu0.16.04.1≥ 0, < 1:60.7.0+build1-0ubuntu0.18.04.12019-05-28
CVE-2019-18511 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass same-origin protections, or execute arbitrary code.
(CVE-2019-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-9797, CVE-2019-9800, CVE-2019-9817, CVE-2019-9819, CVE-2019-9820)
osv
← Previous101 / 101