Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 62 of 101
CVE-2017-5445P3HIGHCVSS 7.5fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5445 [HIGH] CWE-129 CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized val
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2008-1233P3MEDIUMCVSS 6.8≤ 2.0.0.122008-03-27
CVE-2008-1233 [MEDIUM] CWE-94 CVE-2008-1233: Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMo
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."
nvd
CVE-2007-0008P3MEDIUMCVSS 6.8≤ 1.5.0.9v0.1+29 more2007-02-26
CVE-2007-0008 [MEDIUM] CWE-189 CVE-2007-0008: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message
nvd
CVE-2009-0774P3CRITICALCVSS 9.3≤ 2.0.0.20v2.0.0.0+10 more2009-03-05
CVE-2009-0774 [CRITICAL] CVE-2009-0774: The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonke
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
nvd
CVE-2017-5422P3HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5422 [HIGH] CWE-20 CVE-2017-5422: If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can t
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2010-1211P3CRITICALCVSS 9.3v3.0v3.0.1+5 more2010-07-30
CVE-2010-1211 [CRITICAL] CVE-2010-1211: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-0772P3CRITICALCVSS 9.3≤ 2.0.0.20v2.0.0.0+10 more2009-03-05
CVE-2009-0772 [CRITICAL] CWE-399 CVE-2009-0772: The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonke
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.
nvd
CVE-2017-5421P3HIGHCVSS 7.5fixed in 52.0.≥ unspecified, < 522018-06-11
CVE-2017-5421 [HIGH] CWE-20 CVE-2017-5421: A malicious site could spoof the contents of the print preview window if popup windows are enabled,
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loaded. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2022-42927P3HIGHCVSS 8.1fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42927 [HIGH] CWE-346 CVE-2022-42927: A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosv
CVE-2013-1687P3CRITICALCVSS 9.3≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1687 [CRITICAL] CWE-264 CVE-2013-1687: The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox bef
The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly restrict XBL user-defined functions, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges,
nvd
CVE-2019-17010P3HIGHCVSS 7.5fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17010 [HIGH] CWE-362 CVE-2019-17010: Under certain conditions, when checking the Resist Fingerprinting preference during device orientati
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvdosv
CVE-2019-17011P3HIGHCVSS 7.5fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17011 [HIGH] CWE-362 CVE-2019-17011: Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a rac
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvdosv
CVE-2020-6821P3HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.7.02020-04-24
CVE-2020-6821 [HIGH] CWE-908 CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSub
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvdosv
CVE-2007-4841P3CRITICALCVSS 9.3≤ 2.0.0.82007-09-12
CVE-2007-4841 [CRITICAL] CVE-2007-4841: Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote
Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845.
nvd
CVE-2018-12379P3HIGHCVSS 7.8fixed in 60.2.1≥ unspecified, < 60.2.12018-10-18
CVE-2018-12379 [HIGH] CWE-787 CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2
nvdosv
CVE-2019-17009P3HIGHCVSS 7.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17009 [HIGH] CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentiall
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Th
nvd
CVE-2023-4048P3HIGHCVSS 7.5≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4048 [HIGH] CVE-2023-4048: An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2007-0777P3CRITICALCVSS 9.3fixed in 1.5.0.102007-02-26
CVE-2007-0777 [CRITICAL] CWE-119 CVE-2007-0777: The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before
The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.
nvd
CVE-2006-4571P3CRITICALCVSS 10.0≤ 1.5.0.62006-09-15
CVE-2006-4571 [CRITICAL] CVE-2006-4571: Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaM
Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data.
nvdosv
CVE-2009-2465P4CRITICALCVSS 10.0v2.0.0.0v2.0.0.1+19 more2009-07-22
CVE-2009-2465 [CRITICAL] CWE-399 CVE-2009-2465: Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (m
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
nvd