cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 35 of 101
CVE-2013-1677P3CRITICALCVSS 10.0≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1677 [CRITICAL] CWE-399 CVE-2013-1677: The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x befor The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2016-1930P3CRITICALCVSS 9.8≥ 0, < 1:38.6.0+build1-0ubuntu0.14.04.12016-01-26
CVE-2016-1930 [CRITICAL] CVE-2016-1930: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
osv
CVE-2012-3960P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-3960 [CRITICAL] CWE-416 CVE-2012-3960: Use-after-free vulnerability in the mozSpellChecker::SetCurrentDictionary function in Mozilla Firefo Use-after-free vulnerability in the mozSpellChecker::SetCurrentDictionary function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecifi
nvd
CVE-2012-3956P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-3956 [CRITICAL] CWE-416 CVE-2012-3956: Use-after-free vulnerability in the MediaStreamGraphThreadRunnable::Run function in Mozilla Firefox Use-after-free vulnerability in the MediaStreamGraphThreadRunnable::Run function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2020-6800P3HIGHCVSS 8.8fixed in 68.5.0≥ unspecified, < 68.52020-03-02
CVE-2020-6800 [HIGH] CWE-787 CVE-2020-6800: Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product
nvdosv
CVE-2016-1951P3HIGHCVSS 8.6≥ 0, < 1:45.2.0+build1-0ubuntu0.14.04.3≥ 0, < 1:45.2.0+build1-0ubuntu0.16.04.12016-07-18
CVE-2016-1951 [HIGH] thunderbird vulnerabilities thunderbird vulnerabilities It was discovered that NSPR incorrectly handled memory allocation. If a user were tricked in to opening a specially crafted message, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code. (CVE-2016-1951) Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel, Sylvestre Ledru, Julian Seward, Olli Pettay, and Karl Tomlinson, discovered
osv
CVE-2012-3958P3CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3958 [CRITICAL] CWE-399 CVE-2012-3958: Use-after-free vulnerability in the nsHTMLEditRules::DeleteNonTableElements function in Mozilla Fire Use-after-free vulnerability in the nsHTMLEditRules::DeleteNonTableElements function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2007-0776P3CRITICALCVSS 9.3≤ 1.5.0.92007-02-26
CVE-2007-0776 [CRITICAL] CWE-119 CVE-2007-0776: Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Th Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
nvd
CVE-2020-12422P3HIGHCVSS 8.8≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12422 [HIGH] CVE-2020-12422: In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds w In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
osv
CVE-2013-0752P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0752 [CRITICAL] CWE-119 CVE-2013-0752: Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XBL file with multiple bindings that have SVG content.
nvd
CVE-2019-11740P3HIGHCVSS 8.8fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvdosv
CVE-2021-38496P3HIGHCVSS 8.8fixed in 78.15≥ 91.0, < 91.2+2 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvdosv
CVE-2020-12410P3HIGHCVSS 8.8≥ unspecified, < 68.9.02020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2021-29985P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29985 [HIGH] CWE-416 CVE-2021-29985: A use-after-free vulnerability in media channels could have led to memory corruption and a potential A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv
CVE-2021-29984P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29984 [HIGH] CWE-787 CVE-2021-29984: Instruction reordering resulted in a sequence of instructions that would cause an object to be incor Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv
CVE-2021-29967P3HIGHCVSS 8.8fixed in 78.11≥ unspecified, < 78.112021-06-24
CVE-2021-29967 [HIGH] CWE-787 CVE-2021-29967: Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
nvdosv
CVE-2020-6805P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6805 [HIGH] CWE-416 CVE-2020-6805: When removing data about an origin whose tab was recently closed, a use-after-free could occur in th When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvdosv
CVE-2020-6807P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6807 [HIGH] CWE-416 CVE-2020-6807: When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> t When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvdosv
CVE-2020-26970P3HIGHCVSS 8.8fixed in 78.5.12020-12-09
CVE-2020-26970 [HIGH] CWE-787 CVE-2020-26970: When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stac When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
nvdosv
CVE-2021-38501P3HIGHCVSS 8.8fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38501 [HIGH] CVE-2021-38501: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase