Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 31 of 101
CVE-2023-6859P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6859 [HIGH] CWE-416 CVE-2023-6859: A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerabili
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2020-12406P3HIGHCVSS 8.8fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12406 [HIGH] CWE-345 CVE-2020-12406: Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resul
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2022-38477P3HIGHCVSS 8.8fixed in 102.2≥ unspecified, < 102.22022-12-22
CVE-2022-38477 [HIGH] CWE-787 CVE-2022-38477: Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird <
nvdosv
CVE-2023-37202P3HIGHCVSS 8.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37202 [HIGH] CWE-416 CVE-2023-37202: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvdosv
CVE-2004-0903P3CRITICALCVSS 10.0v0.7v0.7.1+2 more2005-01-27
CVE-2004-0903 [CRITICAL] CVE-2004-0903: Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
nvd
CVE-2022-22761P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22761 [HIGH] CWE-693 CVE-2022-22761: Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing t
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdosv
CVE-2022-42932P3HIGHCVSS 8.8fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42932 [HIGH] CWE-787 CVE-2022-42932: Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4
nvdosv
CVE-2022-22764P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22764 [HIGH] CWE-787 CVE-2022-22764: Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, an
nvdosv
CVE-2017-7786P3CRITICALCVSS 9.8fixed in 52.3≥ unspecified, < 52.32018-06-11
CVE-2017-7786 [CRITICAL] CWE-119 CVE-2017-7786: A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements.
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2022-38473P3HIGHCVSS 8.8fixed in 91.13≥ 102.0, < 102.2+2 more2022-12-22
CVE-2022-38473 [HIGH] CWE-281 CVE-2022-38473: A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (su
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
nvdosv
CVE-2023-25744P3HIGHCVSS 8.8≥ 0, < 1:102.8.0-1~deb11u1≥ 0, < 1:102.8.0-12023-06-02
CVE-2023-25744 [HIGH] CVE-2023-25744: Mmemory safety bugs present in Firefox 109 and Firefox ESR 102
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
osv
CVE-2024-7522P3HIGHCVSS 8.8fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7522 [HIGH] CWE-125 CVE-2024-7522: Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This v
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdosv
CVE-2023-4047P3HIGHCVSS 8.8≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4047 [HIGH] CVE-2023-4047: A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2024-4770P3HIGHCVSS 8.8fixed in 115.11.0≥ unspecified, < 115.112024-05-14
CVE-2024-4770 [HIGH] CWE-416 CVE-2024-4770: When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. T
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvdosv
CVE-2024-9400P3HIGHCVSS 8.8fixed in 128.3.0≥ 129.0, < 131.0+2 more2024-10-01
CVE-2024-9400 [HIGH] CWE-119 CVE-2024-9400: A potential memory corruption vulnerability could be triggered if an attacker had the ability to tri
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvdosv
CVE-2017-7824P3CRITICALCVSS 9.8fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7824 [CRITICAL] CWE-119 CVE-2017-7824: A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvdosv
CVE-2017-5433P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5433 [CRITICAL] CWE-416 CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation element
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5434P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5434 [CRITICAL] CWE-416 CVE-2017-5434: A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5439P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5439 [CRITICAL] CWE-416 CVE-2017-5439: A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. T
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-7784P3CRITICALCVSS 9.8fixed in 52.3.02018-06-11
CVE-2017-7784 [CRITICAL] CWE-416 CVE-2017-7784: A use-after-free vulnerability can occur when reading an image observer during frame reconstruction
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd