cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 3 of 101
CVE-2015-4000P3LOWCVSS 3.7PoCv31.8v38.12015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2016-1960P2HIGHCVSS 8.8PoC≤ 38.6.02016-03-13
CVE-2016-1960 [HIGH] CVE-2016-1960: Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox befo Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
nvd
CVE-2017-5447P2CRITICALCVSS 9.1PoCfixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5447 [CRITICAL] CWE-416 CVE-2017-5447: An out-of-bounds read during the processing of glyph widths during text layout. This results in a po An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2015-0816P3MEDIUMCVSS 5.0PoC≤ 31.52015-04-01
CVE-2015-0816 [MEDIUM] CWE-264 CVE-2015-0816: Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not proper Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
nvdosv
CVE-2017-5404P2CRITICALCVSS 9.8PoCfixed in 45.8.0≥ unspecified, < 52+1 more2018-06-11
CVE-2017-5404 [CRITICAL] CWE-416 CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a nativ A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5465P2CRITICALCVSS 9.1PoCfixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5465 [CRITICAL] CWE-125 CVE-2017-5465: An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and a An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2019-11704P2CRITICALCVSS 9.8PoCfixed in 60.7.1≥ unspecified, < 60.7.12019-07-23
CVE-2019-11704 [CRITICAL] CWE-787 CVE-2019-11704: A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_an A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
nvdosv
CVE-2019-11703P2CRITICALCVSS 9.8PoCfixed in 60.7.1≥ unspecified, < 60.7.12019-07-23
CVE-2019-11703 [CRITICAL] CWE-787 CVE-2019-11703: A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
nvdosv
CVE-2019-11705P2CRITICALCVSS 9.8PoCfixed in 60.7.1≥ unspecified, < 60.7.12019-07-23
CVE-2019-11705 [CRITICAL] CWE-787 CVE-2019-11705: A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_byday A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
nvdosv
CVE-2019-9792P2CRITICALCVSS 9.8PoCfixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9792 [CRITICAL] CWE-787 CVE-2019-9792: The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the r The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvdosv
CVE-2019-9813P3HIGHCVSS 8.8PoCfixed in 60.6.1≥ unspecified, < 60.6.12019-04-26
CVE-2019-9813 [HIGH] CWE-843 CVE-2019-9813: Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can b Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
nvd
CVE-2010-3131P3CRITICALCVSS 9.3PoC≤ 3.0.6v0.1+66 more2010-08-26
CVE-2010-3131 [CRITICAL] CVE-2010-3131: Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunder Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder
nvd
CVE-2010-3179P3CRITICALCVSS 9.3PoC≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3179 [CRITICAL] CWE-119 CVE-2010-3179: Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a long argument to the docum
nvd
CVE-2010-1199P3CRITICALCVSS 9.3PoC≤ 3.0.4v0.1+40 more2010-06-24
CVE-2010-1199 [CRITICAL] CWE-189 CVE-2010-1199: Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
nvd
CVE-2010-2752P3CRITICALCVSS 9.3PoCv3.0v3.0.1+5 more2010-07-30
CVE-2010-2752 [CRITICAL] CWE-189 CVE-2010-2752: Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Th Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an
nvd
CVE-2019-11706P3HIGHCVSS 7.5PoCfixed in 60.7.1≥ unspecified, < 60.7.12019-07-23
CVE-2019-11706 [HIGH] CWE-843 CVE-2019-11706: A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.
nvdosv
CVE-2009-2464P3CRITICALCVSS 10.0PoCv2.0.0.0v2.0.0.1+19 more2009-07-22
CVE-2009-2464 [CRITICAL] CWE-399 CVE-2009-2464: The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaM The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.
nvd
CVE-2006-0295P3MEDIUMCVSS 5.1PoCv1.52006-02-02
CVE-2006-0295 [MEDIUM] CVE-2006-0295: Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 migh Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
nvdosv
CVE-2010-0167P3CRITICALCVSS 9.3PoC≤ 3.0.1v1.5+30 more2010-03-25
CVE-2010-0167 [CRITICAL] CWE-119 CVE-2010-0167: The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6. The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (
nvd
CVE-2021-43527P2CRITICALCVSS 9.8≥ unspecified, < 91.3.02021-12-08
CVE-2021-43527 [CRITICAL] CWE-787 CVE-2021-43527: NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overfl NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.50
nvd
Mozilla Thunderbird vulnerabilities | cvebase