cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 64 of 101
CVE-2019-11729P4HIGHCVSS 7.5fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11729 [HIGH] CWE-119 CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperl Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2021-23981P3HIGHCVSS 8.1fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23981 [HIGH] CWE-787 CVE-2021-23981: A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buf A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvdosv
CVE-2008-2806P3HIGHCVSS 7.5v2.0_.4v2.0_.5+6 more2008-07-07
CVE-2008-2806 [HIGH] CWE-20 CVE-2008-2806: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to by Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
nvd
CVE-2009-2210P4CRITICALCVSS 9.3≤ 2.0.0.21v0.1+67 more2009-06-25
CVE-2009-2210 [CRITICAL] CVE-2009-2210: Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a de Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.
nvd
CVE-2008-3835P4HIGHCVSS 7.5≤ 2.0.0.16v0.1+57 more2008-09-24
CVE-2008-3835 [HIGH] CWE-264 CVE-2008-3835: The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
nvd
CVE-2017-5406P4HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5406 [HIGH] CWE-119 CVE-2017-5406: A segmentation fault can occur in the Skia graphics library during some canvas operations due to iss A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2017-5416P4HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5416 [HIGH] CWE-476 CVE-2017-5416: In certain circumstances a networking event listener can be prematurely released. This appears to re In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2014-1592P3MEDIUMCVSS 6.8≤ 31.22014-12-11
CVE-2014-1592 [MEDIUM] CVE-2014-1592: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox befo Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code by adding a second root element to an HTML5 document during parsing.
nvdosv
CVE-2018-18513P4HIGHCVSS 7.5fixed in 60.5.0≥ unspecified, < 60.52019-04-26
CVE-2018-18513 [HIGH] CWE-476 CVE-2018-18513: A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted si A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again. This vulnerability affects Thunderbird < 60.5.
nvdosv
CVE-2010-1212P4CRITICALCVSS 9.3v3.12010-07-30
CVE-2010-1212 [CRITICAL] CWE-119 CVE-2010-1212: js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1. js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function,
nvd
CVE-2020-15657P4HIGHCVSS 7.8fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15657 [HIGH] CWE-427 CVE-2020-15657: Firefox could be made to load attacker-supplied DLL files from the installation directory. This requ Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, an
nvd
CVE-2021-29949P4HIGHCVSS 7.8fixed in 78.9.1≥ unspecified, < 78.9.12021-06-24
CVE-2021-29949 [HIGH] CWE-427 CVE-2021-29949: When loading the shared library that provides the OTR protocol implementation, Thunderbird will init When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in
nvdosv
CVE-2006-1727P4HIGHCVSS 7.6≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1727 [HIGH] CVE-2006-1727: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0 Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
nvdosv
CVE-2025-1933P3HIGHCVSS 7.6fixed in 128.8≥ 129.0, < 136.02025-03-04
CVE-2025-1933 [HIGH] CVE-2025-1933: On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over me On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2006-3805P3HIGHCVSS 7.5v1.5v1.5.0.2+1 more2006-07-27
CVE-2006-3805 [HIGH] CVE-2006-3805: The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey b The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
nvdosv
CVE-2024-0741P3MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0741 [MEDIUM] CWE-787 CVE-2024-0741: An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potent An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2006-2779P4CRITICALCVSS 9.3v0.6v0.7+15 more2006-06-02
CVE-2006-2779 [CRITICAL] CWE-94 CVE-2006-2779: Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service ( Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which l
nvdosv
CVE-2006-3807P3HIGHCVSS 7.5v1.5v1.5.0.2+1 more2006-07-27
CVE-2006-3807 [HIGH] CVE-2006-3807: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
nvdosv
CVE-2006-1734P3MEDIUMCVSS 6.8≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1734 [MEDIUM] CVE-2006-1734: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.
nvdosv
CVE-2023-5388P4MEDIUMCVSS 6.5fixed in 115.9.0≥ unspecified, < 115.92024-03-19
CVE-2023-5388 [MEDIUM] CWE-203 CVE-2023-5388: NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack coul NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase