Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 48 of 91
CVE-2017-7778CRITICALCVSS 9.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7778 [CRITICAL] CWE-119 CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-5410CRITICALCVSS 9.8fixed in 45.8.0≥ unspecified, < 52+1 more2018-06-11
CVE-2017-5410 [CRITICAL] CWE-119 CVE-2017-5410: Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScri Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2018-5104CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5104 [CRITICAL] CWE-416 CVE-2018-5104: A use-after-free vulnerability can occur during font face manipulation when a font face is freed whi A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2017-5413CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5413 [CRITICAL] CWE-119 CVE-2017-5413: A segmentation fault can occur during some bidirectional layout operations. This vulnerability affec A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2017-7793CRITICALCVSS 9.8fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7793 [CRITICAL] CWE-416 CVE-2017-7793: A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window a A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvdosv
CVE-2017-5434CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5434 [CRITICAL] CWE-416 CVE-2017-5434: A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5470CRITICALCVSS 9.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-5470 [CRITICAL] CWE-119 CVE-2017-5470: Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evide Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvdosv
CVE-2017-7802CRITICALCVSS 9.8fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7802 [CRITICAL] CWE-416 CVE-2017-7802: A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an ima A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-7826CRITICALCVSS 9.8fixed in 52.5.0≥ unspecified, < 52.52018-06-11
CVE-2017-7826 [CRITICAL] CWE-119 CVE-2017-7826: Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evide Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvdosv
CVE-2018-5095CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5095 [CRITICAL] CWE-190 CVE-2018-5095: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2016-9893CRITICALCVSS 9.8fixed in 45.6.0≥ unspecified, < 45.62018-06-11
CVE-2016-9893 [CRITICAL] CWE-119 CVE-2016-9893: Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory c Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvdosv
CVE-2018-5155CRITICALCVSS 9.8fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5155 [CRITICAL] CWE-416 CVE-2018-5155: A use-after-free vulnerability can occur while adjusting layout during SVG animations with text path A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvdosv
CVE-2017-7753CRITICALCVSS 9.1fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7753 [CRITICAL] CWE-125 CVE-2017-7753: An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, usi An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvdosv
CVE-2017-7800CRITICALCVSS 9.8fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7800 [CRITICAL] CWE-416 CVE-2017-7800: A use-after-free vulnerability can occur in WebSockets when the object holding the connection is fre A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-5441CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5441 [CRITICAL] CWE-416 CVE-2017-5441: A use-after-free vulnerability when holding a selection during scroll events. This results in a pote A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5429CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5429 [CRITICAL] CWE-119 CVE-2017-5429: Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52 Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Fi
nvdosv
CVE-2017-7751CRITICALCVSS 9.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7751 [CRITICAL] CWE-416 CVE-2017-7751: A use-after-free vulnerability with content viewer listeners that results in a potentially exploitab A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-5443CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5443 [CRITICAL] CWE-787 CVE-2017-5443: An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This v An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-5103CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5103 [CRITICAL] CWE-416 CVE-2018-5103: A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2017-5472CRITICALCVSS 9.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-5472 [CRITICAL] CWE-416 CVE-2017-5472: A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CS A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd