Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 42 of 91
CVE-2019-11763MEDIUMCVSS 6.1fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11763 [MEDIUM] CWE-79 CVE-2019-11763: Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of e
nvdosv
CVE-2019-11761MEDIUMCVSS 5.4fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvdosv
CVE-2019-11762MEDIUMCVSS 6.1fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11762 [MEDIUM] CWE-346 CVE-2019-11762: If two same-origin documents set document.domain differently to become cross-origin, it was possible If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvdosv
CVE-2019-17022MEDIUMCVSS 6.1≥ 0, < 1:68.4.1-12020-01-08
CVE-2019-17022 [MEDIUM] CVE-2019-17022: When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer does not escape characters When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer does not escape characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, t
osv
CVE-2019-17016MEDIUMCVSS 6.1≥ 0, < 1:68.4.1-12020-01-08
CVE-2019-17016 [MEDIUM] CVE-2019-17016: When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
osv
CVE-2019-11746HIGHCVSS 8.8fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11746 [HIGH] CWE-416 CVE-2019-11746: A use-after-free vulnerability can occur while manipulating video elements if the body is freed whil A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvdosv
CVE-2019-11740HIGHCVSS 8.8fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvdosv
CVE-2019-11752HIGHCVSS 8.8fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11752 [HIGH] CWE-416 CVE-2019-11752: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvdosv
CVE-2019-11755HIGHCVSS 7.5fixed in 68.1.1≥ unspecified, < 68.1.12019-09-27
CVE-2019-11755 [HIGH] CWE-347 CVE-2019-11755: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was s A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a di
nvdosv
CVE-2019-11742MEDIUMCVSS 6.5fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11742 [MEDIUM] CWE-829 CVE-2019-11742: A same-origin policy violation occurs allowing the theft of cross-origin images through a combinatio A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbir
nvdosv
CVE-2019-11739MEDIUMCVSS 6.5fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11739 [MEDIUM] CWE-319 CVE-2019-11739: Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included i Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.
nvdosv
CVE-2019-11744MEDIUMCVSS 6.1fixed in 60.9≥ 68.0, < 68.1+2 more2019-09-27
CVE-2019-11744 [MEDIUM] CWE-79 CVE-2019-11744: Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets w Some HTML elements, such as and , can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as
nvdosv
CVE-2019-11743LOWCVSS 3.7fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11743 [LOW] CWE-203 CVE-2019-11743: Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specificati Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affect
nvdosv
CVE-2019-15903HIGHCVSS 7.5≥ 0, < 1:68.2.1-12019-09-04
CVE-2019-15903 [HIGH] CVE-2019-15903: In libexpat before 2 In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
osv
CVE-2019-11691CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-11691 [CRITICAL] CWE-416 CVE-2019-11691: A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, ca A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
CVE-2019-11705CRITICALCVSS 9.8PoCfixed in 60.7.1≥ unspecified, < 60.7.12019-07-23
CVE-2019-11705 [CRITICAL] CWE-787 CVE-2019-11705: A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_byday A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
nvdosv
CVE-2019-11709CRITICALCVSS 9.8fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11709 [CRITICAL] CWE-787 CVE-2019-11709: Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 6
nvdosv
CVE-2019-9800CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9800 [CRITICAL] CWE-787 CVE-2019-9800: Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and
nvdosv
CVE-2019-11713CRITICALCVSS 9.8fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11713 [CRITICAL] CWE-416 CVE-2019-11713: A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2019-9819CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9819 [CRITICAL] CWE-843 CVE-2019-9819: A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase