Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 39 of 91
CVE-2020-15655MEDIUMCVSS 6.5fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15655 [MEDIUM] CVE-2020-15655: A redirected HTTP request which is observed or modified through a web extension could bypass existin A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvdosv
CVE-2020-6514MEDIUMCVSS 6.5≥ 0, < 1:68.11.0-12020-07-22
CVE-2020-6514 [MEDIUM] CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84 Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
osv
CVE-2020-12406HIGHCVSS 8.8fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12406 [HIGH] CWE-345 CVE-2020-12406: Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resul Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2020-12410HIGHCVSS 8.8≥ unspecified, < 68.9.02020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2020-12420HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12420 [HIGH] CWE-362 CVE-2020-12420: When trying to connect to a STUN server, a race condition could have caused a use-after-free of a po When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2020-12417HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2020-12419HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12419 [HIGH] CWE-416 CVE-2020-12419: When processing callbacks that occurred during window flushing in the parent process, the associated When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2020-12398HIGHCVSS 7.5fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12398 [HIGH] CWE-319 CVE-2020-12398: If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH resp If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.
nvdosv
CVE-2018-12371HIGHCVSS 8.8fixed in 60.0≥ unspecified, < 602020-07-09
CVE-2018-12371 [HIGH] CWE-190 CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.
nvdosv
CVE-2020-12399MEDIUMCVSS 4.4fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2020-12418MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12418 [MEDIUM] CWE-125 CVE-2020-12418: Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking proce Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2020-12421MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12421 [MEDIUM] CWE-295 CVE-2020-12421: When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected ( When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2020-12405MEDIUMCVSS 5.3fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12405 [MEDIUM] CWE-362 CVE-2020-12405: When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2020-12416HIGHCVSS 8.8≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12416 [HIGH] CVE-2020-12416: A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
osv
CVE-2020-12422HIGHCVSS 8.8≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12422 [HIGH] CVE-2020-12422: In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds w In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
osv
CVE-2020-12426HIGHCVSS 8.8≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12426 [HIGH] CVE-2020-12426: Mozilla developers and community members reported memory safety bugs present in Firefox 77 Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 78.
osv
CVE-2020-12415MEDIUMCVSS 6.5≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12415 [MEDIUM] CVE-2020-12415: When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.
osv
CVE-2020-12424MEDIUMCVSS 6.5≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12424 [MEDIUM] CVE-2020-12424: When constructing a permission prompt for WebRTC, a URI was supplied from the content process When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.
osv
CVE-2020-12425MEDIUMCVSS 6.5≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12425 [MEDIUM] CVE-2020-12425: Due to confusion processing a hyphen character in Date Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
osv
CVE-2020-6831CRITICALCVSS 9.8fixed in 68.8.0≥ unspecified, < 68.8.02020-05-26
CVE-2020-6831 [CRITICAL] CWE-787 CVE-2020-6831: A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase