Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 29 of 91
CVE-2022-38477HIGHCVSS 8.8fixed in 102.2≥ unspecified, < 102.22022-12-22
CVE-2022-38477 [HIGH] CWE-787 CVE-2022-38477: Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird <
nvdosv
CVE-2022-2505HIGHCVSS 8.8fixed in 102.1≥ unspecified, < 102.12022-12-22
CVE-2022-2505 [HIGH] CWE-787 CVE-2022-2505: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102.
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
nvdosv
CVE-2022-46878HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46878 [HIGH] CWE-787 CVE-2022-46878: Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firef
nvdosv
CVE-2022-22753HIGHCVSS 7.1fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22753 [HIGH] CWE-367 CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6,
nvd
CVE-2022-34468HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34468 [HIGH] CWE-829 CVE-2022-34468: An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascrip
An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2022-22737HIGHCVSS 7.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22737 [HIGH] CWE-362 CVE-2022-22737: Constructing audio sinks could have lead to a race condition when playing audio files and closing wi
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2022-22738HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22738 [HIGH] CWE-787 CVE-2022-22738: Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a hea
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2022-38478HIGHCVSS 8.8fixed in 91.13≥ 102.0, < 102.2+2 more2022-12-22
CVE-2022-38478 [HIGH] CWE-787 CVE-2022-38478: Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13,
nvdosv
CVE-2022-3155HIGHCVSS 7.8fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-3155 [HIGH] CWE-276 CVE-2022-3155: When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.qua
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
nvd
CVE-2020-15685HIGHCVSS 8.8fixed in 78.7.0≥ unspecified, < 78.72022-12-22
CVE-2020-15685 [HIGH] CWE-77 CVE-2020-15685: During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injec
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.
nvdosv
CVE-2022-38473HIGHCVSS 8.8fixed in 91.13≥ 102.0, < 102.2+2 more2022-12-22
CVE-2022-38473 [HIGH] CWE-281 CVE-2022-38473: A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (su
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
nvdosv
CVE-2022-45421HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45421 [HIGH] CWE-787 CVE-2022-45421: Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thund
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox
nvdosv
CVE-2022-22744HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22744 [HIGH] CWE-116 CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped fo
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder
nvd
CVE-2022-40962HIGHCVSS 8.8fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40962 [HIGH] CWE-787 CVE-2022-40962: Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla
Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 104 and Firefox ESR 102.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vuln
nvdosv
CVE-2022-46871HIGHCVSS 8.8≥ 0, < 1:102.8.0-1~deb11u1≥ 0, < 1:102.7.1-12022-12-22
CVE-2022-46871 [HIGH] CVE-2022-46871: An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
osv
CVE-2022-46874HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.6.1+1 more2022-12-22
CVE-2022-46874 [HIGH] CWE-94 CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, lea
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitte
nvdosv
CVE-2022-45409HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45409 [HIGH] CWE-416 CVE-2022-45409: The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finis
The garbage collector could have been aborted in several states and zones and GCRuntime::finishCollection may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2022-1097MEDIUMCVSS 6.5fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-1097 [MEDIUM] CWE-416 CVE-2022-1097: <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an
NSSToken objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvdosv
CVE-2022-40959MEDIUMCVSS 6.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40959 [MEDIUM] CWE-922 CVE-2022-40959: During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading t
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvdosv
CVE-2022-45403MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45403 [MEDIUM] CWE-203 CVE-2022-45403: Service Workers should not be able to infer information about opaque cross-origin responses; but tim
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv