Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 53 of 91
CVE-2016-9079HIGHCVSS 7.5KEVPoCfixed in 45.5.1≥ unspecified, < 45.5.12018-06-11
CVE-2016-9079 [HIGH] CWE-416 CVE-2016-9079: A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulner A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
nvd
CVE-2016-9897HIGHCVSS 7.5fixed in 45.6.0≥ unspecified, < 45.62018-06-11
CVE-2016-9897 [HIGH] CWE-119 CVE-2016-9897: Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5444HIGHCVSS 7.5fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5444 [HIGH] CWE-119 CVE-2017-5444: A buffer overflow vulnerability while parsing "application/http-index-format" format content when th A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-7752HIGHCVSS 8.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7752 [HIGH] CWE-416 CVE-2017-7752: A use-after-free vulnerability during specific user interactions with the input method editor (IME) A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2018-5170MEDIUMCVSS 4.3fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5170 [MEDIUM] CWE-20 CVE-2018-5170: It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2017-7829MEDIUMCVSS 5.3fixed in 52.5.2≥ unspecified, < 52.5.22018-06-11
CVE-2017-7829 [MEDIUM] CWE-20 CVE-2017-7829: It is possible to spoof the sender's email address and display an arbitrary sender address to the em It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
nvdosv
CVE-2017-7763MEDIUMCVSS 5.3fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7763 [MEDIUM] CWE-20 CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-7764MEDIUMCVSS 5.3fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7764 [MEDIUM] CWE-20 CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unico Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syl
nvd
CVE-2017-7791MEDIUMCVSS 5.3fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7791 [MEDIUM] CWE-20 CVE-2017-7791: On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will re On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-5408MEDIUMCVSS 5.3fixed in 45.8.0≥ unspecified, < 52+1 more2018-06-11
CVE-2017-5408 [MEDIUM] CWE-200 CVE-2017-5408: Video files loaded video captions cross-origin without checking for the presence of CORS headers per Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5451MEDIUMCVSS 4.3fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5451 [MEDIUM] CWE-20 CVE-2017-5451: A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2017-5418MEDIUMCVSS 5.3fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5418 [MEDIUM] CWE-125 CVE-2017-5418: An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set patterns. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2018-5185MEDIUMCVSS 6.5fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5185 [MEDIUM] CWE-311 CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerabili Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2017-7830MEDIUMCVSS 6.5fixed in 52.5.0≥ unspecified, < 52.52018-06-11
CVE-2017-7830 [MEDIUM] CVE-2017-7830: The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-ori The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvdosv
CVE-2017-7823MEDIUMCVSS 5.4fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7823 [MEDIUM] CWE-79 CVE-2017-7823: The content security policy (CSP) "sandbox" directive did not create a unique origin for the documen The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 5
nvdosv
CVE-2017-5383MEDIUMCVSS 5.3fixed in 45.7.0≥ unspecified, < 45.72018-06-11
CVE-2017-5383 [MEDIUM] CWE-20 CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger pu URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-5117MEDIUMCVSS 5.3fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvdosv
CVE-2018-5161MEDIUMCVSS 4.3fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5161 [MEDIUM] CWE-20 CVE-2018-5161: Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulne Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2016-9074MEDIUMCVSS 5.9fixed in 45.5.0≥ unspecified, < 45.52018-06-11
CVE-2016-9074 [MEDIUM] CWE-200 CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This is An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2016-5294MEDIUMCVSS 5.5fixed in 45.5.0≥ unspecified, < 45.52018-06-11
CVE-2016-5294 [MEDIUM] CWE-20 CVE-2016-5294: The Mozilla Updater can be made to choose an arbitrary target working directory for output files res The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd