Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 70 of 91
CVE-2012-4180CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-4180 [CRITICAL] CWE-119 CVE-2012-4180: Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firef Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-3990CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3990 [CRITICAL] CWE-416 CVE-2012-3990: Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the nsIContent::GetNameSpaceID function.
nvd
CVE-2012-3993CRITICALCVSS 9.3PoC≤ 15.0.1v1.0+103 more2012-10-10
CVE-2012-3993 [CRITICAL] CWE-269 CVE-2012-3993: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privil
nvd
CVE-2012-3988CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3988 [CRITICAL] CWE-416 CVE-2012-3988: Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunder Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code via vectors involving use of mozRequestFullScreen to enter full-screen mode, and use of the history.ba
nvd
CVE-2012-3989CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3989 [CRITICAL] CWE-119 CVE-2012-3989: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perf Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.
nvd
CVE-2012-3983CRITICALCVSS 10.0fixed in 16.02012-10-10
CVE-2012-3983 [CRITICAL] CWE-119 CVE-2012-3983: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbi Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-4185CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-4185 [CRITICAL] CWE-119 CVE-2012-4185: Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10. Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-5354MEDIUMCVSS 6.8fixed in 16.02012-10-10
CVE-2012-5354 [MEDIUM] CVE-2012-5354: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly hand Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability tha
nvd
CVE-2012-3985MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3985 [MEDIUM] CWE-79 CVE-2012-3985: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly impl Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
nvd
CVE-2012-3994MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3994 [MEDIUM] CWE-79 CVE-2012-3994: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the
nvd
CVE-2012-4184MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-4184 [MEDIUM] CWE-79 CVE-2012-4184: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome pr
nvd
CVE-2012-3984MEDIUMCVSS 6.8fixed in 16.02012-10-10
CVE-2012-3984 [MEDIUM] CVE-2012-3984: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly hand Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.
nvd
CVE-2012-3986MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3986 [MEDIUM] CWE-20 CVE-2012-3986: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
nvd
CVE-2012-3992MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3992 [MEDIUM] CWE-79 CVE-2012-3992: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and hi
nvd
CVE-2012-3958CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3958 [CRITICAL] CWE-399 CVE-2012-3958: Use-after-free vulnerability in the nsHTMLEditRules::DeleteNonTableElements function in Mozilla Fire Use-after-free vulnerability in the nsHTMLEditRules::DeleteNonTableElements function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2012-3964CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3964 [CRITICAL] CWE-399 CVE-2012-3964: Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0, Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-3966CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3966 [CRITICAL] CWE-119 CVE-2012-3966: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ES Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a negative height value in a BMP image within a .ICO file, related to (1) improper handling of the tr
nvd
CVE-2012-1972CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1972 [CRITICAL] CWE-416 CVE-2012-1972: Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Fire Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2012-1970CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1970 [CRITICAL] CWE-119 CVE-2012-1970: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown
nvd
CVE-2012-3967CRITICALCVSS 9.3fixed in 15.02012-08-29
CVE-2012-3967 [CRITICAL] CWE-787 CVE-2012-3967: The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 on Linux, when a large number of sampler uniforms are used, does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a de
nvd