Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 36 of 91
CVE-2021-29957MEDIUMCVSS 4.3fixed in 78.10.2≥ unspecified, < 78.10.22021-06-24
CVE-2021-29957 [MEDIUM] CVE-2021-29957: If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contai If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.
nvdosv
CVE-2021-23993MEDIUMCVSS 6.5fixed in 78.9.1≥ unspecified, < 78.9.12021-06-24
CVE-2021-23993 [MEDIUM] CWE-347 CVE-2021-23993: An attacker may perform a DoS attack to prevent a user from sending encrypted email to a corresponde An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, ca
nvdosv
CVE-2021-29951MEDIUMCVSS 6.5fixed in 78.10.1≥ unspecified, < 78.10.12021-06-24
CVE-2021-29951 [MEDIUM] CWE-269 CVE-2021-29951: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain net The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Not
nvd
CVE-2021-29948LOWCVSS 2.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-29948 [LOW] CWE-362 CVE-2021-29948: Signatures are written to disk before and read during verification, which might be subject to a race Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.
nvdosv
CVE-2021-23961HIGHCVSS 7.4≥ 0, < 1:78.11.0+build1-0ubuntu0.20.04.22021-06-22
CVE-2021-23961 [HIGH] thunderbird vulnerabilities thunderbird vulnerabilities Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, spoof the UI, bypass security restrictions, or execute arbitrary code. (CVE-2021-23961, CVE-2021-23981, CVE-2021-23982, CVE-2021-23987, CVE-2021-23994, CVE-2021-23998, CVE-2
osv
CVE-2021-30547HIGHCVSS 8.8≥ 0, < 1:78.12.0-12021-06-15
CVE-2021-30547 [HIGH] CVE-2021-30547: Out of bounds write in ANGLE in Google Chrome prior to 91 Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
osv
CVE-2021-23981HIGHCVSS 8.1fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23981 [HIGH] CWE-787 CVE-2021-23981: A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buf A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvdosv
CVE-2021-23987HIGHCVSS 8.8fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23987 [HIGH] CWE-787 CVE-2021-23987: Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.
nvdosv
CVE-2021-23982MEDIUMCVSS 6.5fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23982 [MEDIUM] CWE-326 CVE-2021-23982: Using techniques that built on the slipstream research, a malicious webpage could have scanned both Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvdosv
CVE-2021-23984MEDIUMCVSS 6.5fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23984 [MEDIUM] CWE-290 CVE-2021-23984: A malicious extension could have opened a popup window lacking an address bar. The title of the popu A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, a
nvdosv
CVE-2021-23964HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23964 [HIGH] CWE-787 CVE-2021-23964: Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of t Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvdosv
CVE-2021-23960HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23960 [HIGH] CVE-2021-23960: Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, a Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvdosv
CVE-2021-23978HIGHCVSS 8.8fixed in 78.82021-02-26
CVE-2021-23978 [HIGH] CWE-787 CVE-2021-23978: Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of t Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvdosv
CVE-2021-23954HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23954 [HIGH] CWE-843 CVE-2021-23954: Using the new logical assignment operators in a JavaScript switch statement could have caused a type Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvdosv
CVE-2021-23953MEDIUMCVSS 4.3fixed in 78.72021-02-26
CVE-2021-23953 [MEDIUM] CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cro If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvdosv
CVE-2021-23968MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23968 [MEDIUM] CWE-209 CVE-2021-23968: If Content Security Policy blocked frame navigation, the full destination of a redirect served in th If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvdosv
CVE-2021-23973MEDIUMCVSS 6.5fixed in 78.82021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvdosv
CVE-2021-23969MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23969 [MEDIUM] CVE-2021-23969: As specified in the W3C Content Security Policy draft, when creating a violation report, "User agent As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the s
nvdosv
CVE-2020-16044HIGHCVSS 8.8≥ 0, < 1:78.6.1-12021-02-09
CVE-2020-16044 [HIGH] CVE-2020-16044: Use after free in WebRTC in Google Chrome prior to 88 Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
osv
CVE-2020-16042MEDIUMCVSS 6.5≥ 0, < 1:78.6.0-12021-01-08
CVE-2020-16042 [MEDIUM] CVE-2020-16042: Uninitialized Use in V8 in Google Chrome prior to 87 Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
osv