cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 36 of 101
CVE-2022-34484P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34484 [HIGH] CWE-416 CVE-2022-34484: The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of th The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11
nvdosv
CVE-2014-1549P3CRITICALCVSS 9.3≤ 24.7v24.0+8 more2014-07-23
CVE-2014-1549 [CRITICAL] CWE-119 CVE-2014-1549: The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox befor The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted audio content that is impro
nvdosv
CVE-2020-15685P3HIGHCVSS 8.8fixed in 78.7.0≥ unspecified, < 78.72022-12-22
CVE-2020-15685 [HIGH] CWE-77 CVE-2020-15685: During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injec During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.
nvdosv
CVE-2023-6873P3HIGHCVSS 8.8≥ 0, < 1:115.6.0-1~deb11u1≥ 0, < 1:115.6.0-1~deb12u12023-12-19
CVE-2023-6873 [HIGH] CVE-2023-6873: Memory safety bugs present in Firefox 120 Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
osv
CVE-2022-42928P3HIGHCVSS 8.8fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42928 [HIGH] CWE-476 CVE-2022-42928: Certain types of allocations were missing annotations that, if the Garbage Collector was in a specif Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosv
CVE-2022-2505P3HIGHCVSS 8.8fixed in 102.1≥ unspecified, < 102.12022-12-22
CVE-2022-2505 [HIGH] CWE-787 CVE-2022-2505: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
nvdosv
CVE-2023-25732P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25732 [HIGH] CWE-787 CVE-2023-25732: When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input bein When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2022-46878P3HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46878 [HIGH] CWE-787 CVE-2022-46878: Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firef
nvdosv
CVE-2023-25735P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25735 [HIGH] CWE-416 CVE-2023-25735: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2022-45421P3HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45421 [HIGH] CWE-787 CVE-2022-45421: Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thund Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox
nvdosv
CVE-2022-28289P3HIGHCVSS 8.8fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28289 [HIGH] CWE-787 CVE-2022-28289: Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mo Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability
nvdosv
CVE-2017-7785P3CRITICALCVSS 9.8fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7785 [CRITICAL] CWE-119 CVE-2017-7785: A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attribute A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2018-12393P3HIGHCVSS 7.5fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12393 [HIGH] CWE-190 CVE-2018-12393: A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox
nvd
CVE-2022-22763P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22763 [HIGH] CWE-362 CVE-2022-22763: When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdosv
CVE-2024-6615P3HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6615 [HIGH] CWE-787 CVE-2024-6615: Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2013-0779P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0779 [CRITICAL] CWE-125 CVE-2013-0779: The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0 The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2017-5400P3CRITICALCVSS 9.8fixed in 45.8.0≥ unspecified, < 52+1 more2018-06-11
CVE-2017-5400 [CRITICAL] CWE-119 CVE-2017-5400: JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protection JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2010-3168P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3168 [CRITICAL] CWE-119 CVE-2010-3168: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary
nvd
CVE-2018-18501P3CRITICALCVSS 9.8fixed in 60.5≥ unspecified, < 60.52019-02-05
CVE-2018-18501 [CRITICAL] CWE-119 CVE-2018-18501: Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox <
nvdosv
CVE-2018-5154P3CRITICALCVSS 9.8fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5154 [CRITICAL] CWE-416 CVE-2018-5154: A use-after-free vulnerability can occur while enumerating attributes during SVG animations with cli A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase