Mozilla Thunderbird vulnerabilities
1,918 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,918
CISA KEV
14
actively exploited
Public exploits
59
Exploited in wild
18
Severity breakdown
CRITICAL625HIGH610MEDIUM652LOW31
Vulnerabilities
Page 25 of 96
CVE-2024-0750HIGHCVSS 8.8≤ 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0750 [HIGH] CWE-451 CVE-2024-0750: A bug in popup notifications delay calculation could have made it possible for an attacker to trick
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0743HIGHCVSS 7.5≥ unspecified, < 115.92024-01-23
CVE-2024-0743 [HIGH] CWE-252 CVE-2024-0743: An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. T
An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
CVE-2024-0755HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0755 [HIGH] CWE-94 CVE-2024-0755: Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these b
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0751HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0751 [HIGH] CWE-269 CVE-2024-0751: A malicious devtools extension could have been used to escalate privileges. This vulnerability affec
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0749MEDIUMCVSS 4.3fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0749 [MEDIUM] CWE-346 CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
nvdosv
CVE-2024-0747MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0747 [MEDIUM] CWE-693 CVE-2024-0747: When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Pol
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0741MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0741 [MEDIUM] CWE-787 CVE-2024-0741: An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potent
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0742MEDIUMCVSS 4.3fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0742 [MEDIUM] CVE-2024-0742: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0753MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0753 [MEDIUM] CVE-2024-0753: In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerabil
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2024-0746MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0746 [MEDIUM] CWE-416 CVE-2024-0746: A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerabi
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2023-6864HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6864 [HIGH] CWE-787 CVE-2023-6864: Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these b
Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2023-6873HIGHCVSS 8.8≥ 0, < 1:115.6.0-1~deb11u1≥ 0, < 1:115.6.0-1~deb12u12023-12-19
CVE-2023-6873 [HIGH] CVE-2023-6873: Memory safety bugs present in Firefox 120
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
osv
CVE-2023-6862HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6862 [HIGH] CWE-416 CVE-2023-6862: A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely
A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6.
nvdosv
CVE-2023-6858HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6858 [HIGH] CWE-787 CVE-2023-6858: Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handli
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2023-6859HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6859 [HIGH] CWE-416 CVE-2023-6859: A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerabili
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2023-6856HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6856 [HIGH] CWE-787 CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on syst
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2023-6863HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6863 [HIGH] CVE-2023-6863: The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2023-6861HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6861 [HIGH] CWE-787 CVE-2023-6861: The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in he
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2023-50762MEDIUMCVSS 4.3fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-50762 [MEDIUM] CVE-2023-50762: When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the t
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to
nvdosv
CVE-2023-6860MEDIUMCVSS 6.5fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6860 [MEDIUM] CVE-2023-6860: The `VideoBridge` allowed any content process to use textures produced by remote decoders. This cou
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv