Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 34 of 91
CVE-2021-43541MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43541 [MEDIUM] CVE-2021-43541: When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces w
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
CVE-2021-38509MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2021-43545MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
CVE-2021-38501HIGHCVSS 8.8fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38501 [HIGH] CVE-2021-38501: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2021-38496HIGHCVSS 8.8fixed in 78.15≥ 91.0, < 91.2+2 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvdosv
CVE-2021-29991HIGHCVSS 8.1fixed in 91.0.1≥ unspecified, < 91.0.12021-11-03
CVE-2021-29991 [HIGH] CWE-444 CVE-2021-29991: Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers.
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
nvdosv
CVE-2021-38500HIGHCVSS 8.8fixed in 78.15≥ 91.0, < 91.2+2 more2021-11-03
CVE-2021-38500 [HIGH] CVE-2021-38500: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and
nvdosv
CVE-2021-38498HIGHCVSS 7.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38498 [HIGH] CWE-416 CVE-2021-38498: During process shutdown, a document could have caused a use-after-free of a languages service object
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2021-38495HIGHCVSS 8.8fixed in 91.1≥ unspecified, < 91.12021-11-03
CVE-2021-38495 [HIGH] CWE-787 CVE-2021-38495: Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs sh
Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.1 and Firefox ESR < 91.1.
nvdosv
CVE-2021-38493HIGHCVSS 8.8fixed in 78.14≥ unspecified, < 78.142021-11-03
CVE-2021-38493 [HIGH] CWE-787 CVE-2021-38493: Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
nvdosv
CVE-2021-38502MEDIUMCVSS 5.9fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38502 [MEDIUM] CVE-2021-38502: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM co
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication
nvdosv
CVE-2021-38497MEDIUMCVSS 6.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38497 [MEDIUM] CWE-346 CVE-2021-38497: Through use of reportValidity() and window.open(), a plain-text validation message could have been o
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2021-38492MEDIUMCVSS 6.5fixed in 78.14≥ 91.0, < 91.1+2 more2021-11-03
CVE-2021-38492 [MEDIUM] CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which migh
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 7
nvd
CVE-2021-40529MEDIUMCVSS 5.9fixed in 91.12.02021-09-06
CVE-2021-40529 [MEDIUM] CWE-327 CVE-2021-40529: The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allow
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exp
nvd
CVE-2021-29986HIGHCVSS 8.1fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29986 [HIGH] CWE-362 CVE-2021-29986: A suspected race condition when calling getaddrinfo led to memory corruption and a potentially explo
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv
CVE-2021-29981HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29981 [HIGH] CVE-2021-29981: An issue present in lowering/register allocation could have led to obscure but deterministic registe
An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a potentially exploitable crash. This vulnerability affects Firefox < 91 and Thunderbird < 91.
nvdosv
CVE-2021-29984HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29984 [HIGH] CWE-787 CVE-2021-29984: Instruction reordering resulted in a sequence of instructions that would cause an object to be incor
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv
CVE-2021-29989HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29989 [HIGH] CWE-787 CVE-2021-29989: Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of
Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.13, Firefox ESR < 78.13, and Firefox < 91.
nvdosv
CVE-2021-29985HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29985 [HIGH] CWE-416 CVE-2021-29985: A use-after-free vulnerability in media channels could have led to memory corruption and a potential
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv
CVE-2021-29988HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29988 [HIGH] CWE-125 CVE-2021-29988: Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of b
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv