Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 59 of 101
CVE-2011-2991P3CRITICALCVSS 10.0≤ 5.0v0.1+79 more2011-08-18
CVE-2011-2991 [CRITICAL] CWE-119 CVE-2011-2991: The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6,
The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement JavaScript, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2011-3654P3CRITICALCVSS 10.0≤ 7.0.1v0.1+97 more2011-11-09
CVE-2011-3654 [CRITICAL] CWE-119 CVE-2011-3654: The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle
The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2004-0902P3CRITICALCVSS 10.0v0.7v0.7.1+2 more2005-01-27
CVE-2004-0902 [CRITICAL] CVE-2004-0902: Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII
nvd
CVE-2015-7176P3HIGHCVSS 7.5≥ 0, < 1:38.3.0+build1-0ubuntu0.14.04.12015-09-22
CVE-2015-7176 [HIGH] CVE-2015-7176: The AnimationThread function in Mozilla Firefox before 41
The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.
osv
CVE-2013-0749P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0749 [CRITICAL] CVE-2013-0749: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2019-11712P3HIGHCVSS 8.8fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11712 [HIGH] CWE-352 CVE-2019-11712: POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2015-7194P3HIGHCVSS 7.5≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-7194 [HIGH] CVE-2015-7194: Buffer underflow in libjar in Mozilla Firefox before 42
Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP archive.
osv
CVE-2008-5024P3HIGHCVSS 7.5≥ 2.0, < 2.0.0.182008-11-13
CVE-2008-5024 [HIGH] CWE-91 CVE-2008-5024: Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
nvd
CVE-2017-7807P3HIGHCVSS 8.1fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7807 [HIGH] CWE-20 CVE-2017-7807: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2007-1282P3CRITICALCVSS 9.3v0.1v0.2+28 more2007-03-06
CVE-2007-1282 [CRITICAL] CVE-2007-1282: Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote att
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
nvd
CVE-2012-0442P3CRITICALCVSS 9.3fixed in 3.1.18≥ 5.0, < 10.02012-02-01
CVE-2012-0442 [CRITICAL] CVE-2012-0442: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3176P3CRITICALCVSS 9.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3176 [CRITICAL] CVE-2010-3176: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-1940P3CRITICALCVSS 9.3v5.0v6.0+14 more2012-06-05
CVE-2012-1940 [CRITICAL] CWE-399 CVE-2012-1940: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application cra
nvd
CVE-2015-7193P3HIGHCVSS 7.5≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-7193 [HIGH] CVE-2015-7193: Mozilla Firefox before 42
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
osv
CVE-2016-9904P3HIGHCVSS 7.5fixed in 45.6.0≥ unspecified, < 45.62018-06-11
CVE-2016-9904 [HIGH] CWE-200 CVE-2016-9904: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by ano
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-7754P3HIGHCVSS 7.5fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7754 [HIGH] CWE-125 CVE-2017-7754: An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2014-1490P3CRITICALCVSS 9.3fixed in 24.3.02014-02-06
CVE-2014-1490 [CRITICAL] CWE-362 CVE-2014-1490: Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozill
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involv
nvd
CVE-2015-7213P3MEDIUMCVSS 6.8≥ 0, < 1:38.5.1+build2-0ubuntu0.14.04.12015-12-15
CVE-2015-7213 [MEDIUM] CVE-2015-7213: Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor
Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.
osv
CVE-2013-1725P3MEDIUMCVSS 6.8≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1725 [MEDIUM] CWE-119 CVE-2013-1725: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.
nvd
CVE-2010-3175P3CRITICALCVSS 9.3v3.1v3.1.1+3 more2010-10-21
CVE-2010-3175 [CRITICAL] CVE-2010-3175: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 and Thunderbird 3.1.x before 3.1.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd