Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 17 of 91
CVE-2024-7520HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7520 [HIGH] CWE-843 CVE-2024-7520: A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code ex
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvd
CVE-2024-7525HIGHCVSS 8.1fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7525 [HIGH] CWE-276 CVE-2024-7525: It was possible for a web extension with minimal permissions to create a `StreamFilter` which could
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvdosv
CVE-2024-7528HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7528 [HIGH] CWE-416 CVE-2024-7528: Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulne
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvd
CVE-2024-7527HIGHCVSS 8.8fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7527 [HIGH] CWE-416 CVE-2024-7527: Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerabil
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvdosv
CVE-2024-7526MEDIUMCVSS 6.5fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7526 [MEDIUM] CWE-908 CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvdosv
CVE-2024-7529MEDIUMCVSS 6.5fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvdosv
CVE-2024-7518MEDIUMCVSS 6.5fixed in 128.1≥ unspecified, < 128.12024-08-06
CVE-2024-7518 [MEDIUM] CWE-1021 CVE-2024-7518: Select options could obscure the fullscreen notification dialog. This could be used by a malicious s
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvd
CVE-2024-6602CRITICALCVSS 9.8fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6611CRITICALCVSS 9.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6611 [CRITICAL] CWE-1275 CVE-2024-6611: A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6606HIGHCVSS 8.2fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6606 [HIGH] CWE-125 CVE-2024-6606: Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6609HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6609 [HIGH] CVE-2024-6609: When almost out-of-memory an elliptic curve key which was never allocated could have been freed agai
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6615HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6615 [HIGH] CWE-787 CVE-2024-6615: Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6607HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6607 [HIGH] CWE-763 CVE-2024-6607: It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay custo
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a ` ` element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6603HIGHCVSS 7.4fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6604HIGHCVSS 7.5fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6604 [HIGH] CWE-120 CVE-2024-6604: Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6610MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6610 [MEDIUM] CWE-451 CVE-2024-6610: Form validation popups could capture escape key presses. Therefore, spamming form validation message
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6601MEDIUMCVSS 4.7fixed in 128.0≥ unspecified, < 115.13+1 more2024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6613MEDIUMCVSS 5.5fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6613 [MEDIUM] CWE-209 CVE-2024-6613: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6608MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6608 [MEDIUM] CVE-2024-6608: It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6600MEDIUMCVSS 6.3fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvdosv