Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 55 of 91
CVE-2016-1951HIGHCVSS 8.6≥ 0, < 1:45.2.0+build1-0ubuntu0.14.04.3≥ 0, < 1:45.2.0+build1-0ubuntu0.16.04.12016-07-18
CVE-2016-1951 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that NSPR incorrectly handled memory allocation. If a
user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-1951)
Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel,
Sylvestre Ledru, Julian Seward, Olli Pettay, and Karl Tomlinson,
discovered
osv
CVE-2016-2805MEDIUMCVSS 6.5≥ 0, < 1:38.8.0+build1-0ubuntu0.14.04.1≥ 0, < 1:38.8.0+build1-0ubuntu0.16.04.12016-05-19
CVE-2016-2805 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect r
osv
CVE-2016-1960HIGHCVSS 8.8PoC≤ 38.6.02016-03-13
CVE-2016-1960 [HIGH] CVE-2016-1960: Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox befo
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
nvd
CVE-2016-1966HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1966 [HIGH] CVE-2016-1966: The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox b
The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin.
nvd
CVE-2016-1952HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1952 [HIGH] CWE-119 CVE-2016-1952: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2016-1954HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1954 [HIGH] CWE-264 CVE-2016-1954: The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a
nvd
CVE-2016-1974HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1974 [HIGH] CWE-119 CVE-2016-1974: The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
nvd
CVE-2016-1961HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1961 [HIGH] CVE-2016-1961: Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.
nvd
CVE-2016-1964HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1964 [HIGH] CVE-2016-1964: Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Fir
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
nvd
CVE-2016-1953HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1953 [HIGH] CWE-119 CVE-2016-1953: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
nvd
CVE-2016-1957MEDIUMCVSS 4.3≤ 38.6.02016-03-13
CVE-2016-1957 [MEDIUM] CWE-119 CVE-2016-1957: Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
nvd
CVE-2015-7575MEDIUMCVSS 5.9≥ 0, < 1:38.6.0+build1-0ubuntu0.14.04.12016-03-08
CVE-2015-7575 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
view sensitive information. (CVE-2015-7575)
Yves Younan discovered that graphite2 incorrectly handled certain malformed
fonts. If a user were tricked into opening a specially crafted website i
osv
CVE-2016-1522HIGHCVSS 8.8≤ 38.5.12016-02-13
CVE-2016-1522 [HIGH] CWE-119 CVE-2016-1522: Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
nvd
CVE-2016-1521HIGHCVSS 8.8≤ 38.5.12016-02-13
CVE-2016-1521 [HIGH] CWE-119 CVE-2016-1521: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla F
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application cras
nvd
CVE-2016-1526HIGHCVSS 8.1≤ 38.5.12016-02-13
CVE-2016-1526 [HIGH] CWE-119 CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozill
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smar
nvd
CVE-2016-1523MEDIUMCVSS 6.5≤ 38.5.12016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvd
CVE-2016-1930CRITICALCVSS 9.8≥ 0, < 1:38.6.0+build1-0ubuntu0.14.04.12016-01-26
CVE-2016-1930 [CRITICAL] CVE-2016-1930: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
osv
CVE-2016-1935HIGHCVSS 8.8≥ 0, < 1:38.6.0+build1-0ubuntu0.14.04.12016-01-26
CVE-2016-1935 [HIGH] CVE-2016-1935: Buffer overflow in the BufferSubData function in Mozilla Firefox before 44
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
osv
CVE-2015-7201CRITICALCVSS 10.0≥ 0, < 1:38.5.1+build2-0ubuntu0.14.04.12016-01-13
CVE-2015-7201 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Andrei Vaida, Jesse Ruderman, Bob Clary, and Jesse Ruderman
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-7201)
Ronald Crane discovered a buffer overflow
osv
CVE-2015-7205CRITICALCVSS 10.0≥ 0, < 1:38.5.1+build2-0ubuntu0.14.04.12015-12-15
CVE-2015-7205 [CRITICAL] CVE-2015-7205: Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43
Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.
osv