Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 44 of 91
CVE-2019-11717MEDIUMCVSS 5.3fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2019-11698MEDIUMCVSS 5.3fixed in 60.7.0≥ unspecified, < 60.72019-07-23
CVE-2019-11698 [MEDIUM] CWE-20 CVE-2019-11698: If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookm If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This
nvdosv
CVE-2019-5785MEDIUMCVSS 6.5≥ 0, < 1:60.5.1-12019-06-27
CVE-2019-5785 [MEDIUM] CVE-2019-5785: Incorrect convexity calculations in Skia in Google Chrome prior to 72 Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
osv
CVE-2019-18511CRITICALCVSS 9.8≥ 0, < 1:60.7.0+build1-0ubuntu0.16.04.1≥ 0, < 1:60.7.0+build1-0ubuntu0.18.04.12019-05-28
CVE-2019-18511 [CRITICAL] thunderbird vulnerabilities thunderbird vulnerabilities Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, bypass same-origin protections, or execute arbitrary code. (CVE-2019-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693, CVE-2019-9797, CVE-2019-9800, CVE-2019-9817, CVE-2019-9819, CVE-2019-9820)
osv
CVE-2019-5798MEDIUMCVSS 6.5≥ 0, < 1:60.7.0-12019-05-23
CVE-2019-5798 [MEDIUM] CVE-2019-5798: Lack of correct bounds checking in Skia in Google Chrome prior to 73 Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
osv
CVE-2018-18512CRITICALCVSS 9.8fixed in 65.0≥ unspecified, < 60.52019-04-26
CVE-2018-18512 [CRITICAL] CWE-416 CVE-2018-18512: A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memo A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.
nvdosv
CVE-2019-9792CRITICALCVSS 9.8PoCfixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9792 [CRITICAL] CWE-787 CVE-2019-9792: The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the r The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvdosv
CVE-2019-9788CRITICALCVSS 9.8fixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9788 [CRITICAL] CWE-787 CVE-2019-9788: Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.
nvdosv
CVE-2019-9796CRITICALCVSS 9.8fixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9796 [CRITICAL] CWE-416 CVE-2019-9796: A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers wi A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array.
nvdosv
CVE-2019-9795CRITICALCVSS 9.8fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9795 [CRITICAL] CWE-617 CVE-2019-9795: A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvdosv
CVE-2019-9791CRITICALCVSS 9.8PoCfixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9791 [CRITICAL] CWE-843 CVE-2019-9791: The type inference system allows the compilation of functions that can cause type confusions between The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable
nvdosv
CVE-2019-9794CRITICALCVSS 9.8fixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9794 [CRITICAL] CWE-88 CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded duri A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third part
nvd
CVE-2019-9790CRITICALCVSS 9.8≤ 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9790 [CRITICAL] CWE-416 CVE-2019-9790: A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained u A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvdosv
CVE-2019-9813HIGHCVSS 8.8PoCfixed in 60.6.1≥ unspecified, < 60.6.12019-04-26
CVE-2019-9813 [HIGH] CWE-843 CVE-2019-9813: Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can b Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
nvd
CVE-2019-9810HIGHCVSS 8.8ExploitedPoCfixed in 60.6.1≥ unspecified, < 60.6.12019-04-26
CVE-2019-9810 [HIGH] CWE-119 CVE-2019-9810: Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to m Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
nvd
CVE-2018-18513HIGHCVSS 7.5fixed in 60.5.0≥ unspecified, < 60.52019-04-26
CVE-2018-18513 [HIGH] CWE-476 CVE-2018-18513: A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted si A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again. This vulnerability affects Thunderbird < 60.5.
nvdosv
CVE-2018-18511MEDIUMCVSS 4.3≥ 0, < 1:60.7.0-12019-04-26
CVE-2018-18511 [MEDIUM] CVE-2018-18511: Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
osv
CVE-2019-9801MEDIUMCVSS 5.3fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9801 [MEDIUM] CWE-20 CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch th Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. O
nvd
CVE-2019-9793MEDIUMCVSS 5.9fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9793 [MEDIUM] CWE-119 CVE-2019-9793: A mechanism was discovered that removes some bounds checking for string, array, or typed array acces A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have
nvdosv
CVE-2019-9797MEDIUMCVSS 5.3≥ 0, < 1:60.7.0-12019-04-26
CVE-2019-9797 [MEDIUM] CVE-2019-9797: Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
osv