Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 47 of 101
CVE-2022-22738P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22738 [HIGH] CWE-787 CVE-2022-22738: Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a hea
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2022-34468P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34468 [HIGH] CWE-829 CVE-2022-34468: An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascrip
An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2022-46871P3HIGHCVSS 8.8≥ 0, < 1:102.8.0-1~deb11u1≥ 0, < 1:102.7.1-12022-12-22
CVE-2022-46871 [HIGH] CVE-2022-46871: An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
osv
CVE-2022-29909P3HIGHCVSS 8.8fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29909 [HIGH] CWE-276 CVE-2022-29909: Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvdosv
CVE-2015-7212P3HIGHCVSS 7.5≥ 0, < 1:38.5.1+build2-0ubuntu0.14.04.12015-12-15
CVE-2015-7212 [HIGH] CVE-2015-7212: Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43
Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.
osv
CVE-2022-45412P3HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45412 [HIGH] CWE-59 CVE-2022-45412: When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produc
When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird
nvdosv
CVE-2022-34481P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34481 [HIGH] CWE-190 CVE-2022-34481: In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occu
In the nsTArray_Impl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2023-32213P3HIGHCVSS 8.8fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32213 [HIGH] CWE-908 CVE-2023-32213: When reading a file, an uninitialized value could have been used as read limit. This vulnerability a
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdosv
CVE-2014-1541P3CRITICALCVSS 10.0≤ 24.5v24.0+6 more2014-06-11
CVE-2014-1541 [CRITICAL] CVE-2014-1541: Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Co
Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
nvdosv
CVE-2022-46881P3HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46881 [HIGH] CWE-787 CVE-2022-46881: An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash.
*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR <
nvdosv
CVE-2022-31741P3HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31741 [HIGH] CWE-908 CVE-2022-31741: A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdosv
CVE-2012-3995P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3995 [CRITICAL] CWE-125 CVE-2012-3995: The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, T
The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3232P3CRITICALCVSS 9.3≤ 6.0.2v0.1+96 more2011-09-29
CVE-2011-3232 [CRITICAL] CWE-94 CVE-2011-3232: YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allow
YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
nvd
CVE-2012-1938P3CRITICALCVSS 9.3fixed in 13.02012-06-05
CVE-2012-1938 [CRITICAL] CVE-2012-1938: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 13.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 13.0, Thunderbird before 13.0, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) methodjit/ImmutableSync.cpp, (2) the JSObject::makeDenseArray
nvd
CVE-2012-1949P3CRITICALCVSS 9.3v5.0v6.0+15 more2012-07-18
CVE-2012-1949 [CRITICAL] CVE-2012-1949: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Thun
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-1937P3CRITICALCVSS 9.3v5.0v6.0+14 more2012-06-05
CVE-2012-1937 [CRITICAL] CVE-2012-1937: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 12.0, Fire
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknow
nvd
CVE-2014-1518P3HIGHCVSS 8.8fixed in 24.52014-04-30
CVE-2014-1518 [HIGH] CVE-2014-1518: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-2710P3MEDIUMCVSS 6.8≤ 31.52015-05-14
CVE-2015-2710 [MEDIUM] CWE-119 CVE-2015-2710: Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.
Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
nvdosv
CVE-2008-5022P3HIGHCVSS 7.5≥ 2.0, < 2.0.0.182008-11-13
CVE-2008-5022 [HIGH] CWE-287 CVE-2008-5022: The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.
The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.
nvd
CVE-2017-5373P3CRITICALCVSS 9.8fixed in 45.7.0≥ unspecified, < 45.72018-06-11
CVE-2017-5373 [CRITICAL] CWE-119 CVE-2017-5373: Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evi
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd