Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 28 of 91
CVE-2022-45414HIGHCVSS 8.1fixed in 102.5.12022-12-22
CVE-2022-45414 [HIGH] CVE-2022-45414: If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was sh
nvdosv
CVE-2022-22741HIGHCVSS 7.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22741 [HIGH] CVE-2022-22741: When resizing a popup while requesting fullscreen access, the popup would have become unable to leav
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2022-22764HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22764 [HIGH] CWE-787 CVE-2022-22764: Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, an
nvdosv
CVE-2022-22761HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22761 [HIGH] CWE-693 CVE-2022-22761: Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing t
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdosv
CVE-2022-28281HIGHCVSS 8.8fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28281 [HIGH] CWE-787 CVE-2022-28281: If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register comm
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvdosv
CVE-2022-42927HIGHCVSS 8.1fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42927 [HIGH] CWE-346 CVE-2022-42927: A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosv
CVE-2022-31741HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31741 [HIGH] CWE-908 CVE-2022-31741: A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdosv
CVE-2022-26485HIGHCVSS 8.8KEVfixed in 91.6.2≥ unspecified, < 91.6.22022-12-22
CVE-2022-26485 [HIGH] CWE-416 CVE-2022-26485: Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We ha
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
nvdosv
CVE-2022-28289HIGHCVSS 8.8fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28289 [HIGH] CWE-787 CVE-2022-28289: Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mo
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability
nvdosv
CVE-2022-31740HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31740 [HIGH] CWE-119 CVE-2022-31740: On arm64, WASM code could have resulted in incorrect assembly generation leading to a register alloc
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdosv
CVE-2022-26381HIGHCVSS 8.8fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26381 [HIGH] CWE-416 CVE-2022-26381: An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvdosv
CVE-2022-1802HIGHCVSS 8.8Exploitedfixed in 91.9.1≥ unspecified, < 91.9.12022-12-22
CVE-2022-1802 [HIGH] CWE-1321 CVE-2022-1802: If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollut
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
nvdosv
CVE-2022-26387HIGHCVSS 7.5fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26387 [HIGH] CWE-367 CVE-2022-26387: When installing an add-on, Firefox verified the signature before prompting the user; but while the u
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvdosv
CVE-2022-45412HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45412 [HIGH] CWE-59 CVE-2022-45412: When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produc
When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird
nvdosv
CVE-2022-38476HIGHCVSS 7.5fixed in 102.2≥ unspecified, < 102.22022-12-22
CVE-2022-38476 [HIGH] CWE-416 CVE-2022-38476: A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-aft
A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
nvdosv
CVE-2022-34481HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34481 [HIGH] CWE-190 CVE-2022-34481: In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occu
In the nsTArray_Impl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2022-1529HIGHCVSS 8.8Exploitedfixed in 91.9.1≥ unspecified, < 91.9.12022-12-22
CVE-2022-1529 [HIGH] CWE-1321 CVE-2022-1529: An attacker could have sent a message to the parent process where the contents were used to double-i
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and
nvdosv
CVE-2022-42928HIGHCVSS 8.8fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42928 [HIGH] CWE-476 CVE-2022-42928: Certain types of allocations were missing annotations that, if the Garbage Collector was in a specif
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosv
CVE-2022-22756HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22756 [HIGH] CWE-94 CVE-2022-22756: If a user was convinced to drag and drop an image to their desktop or other folder, the resulting ob
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdosv
CVE-2022-0566HIGHCVSS 8.8fixed in 91.6.1≥ unspecified, < 91.6.12022-12-22
CVE-2022-0566 [HIGH] CWE-787 CVE-2022-0566: It may be possible for an attacker to craft an email message that causes Thunderbird to perform an o
It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.
nvdosv