cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 77 of 101
CVE-2014-1587P4MEDIUMCVSS 6.8≤ 31.22014-12-11
CVE-2014-1587 [MEDIUM] CWE-20 CVE-2014-1587: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2008-1380P4CRITICALCVSS 9.3≤ 2.0.0.13v2.0.0.0+10 more2008-04-17
CVE-2008-1380 [CRITICAL] CVE-2008-1380: The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
nvd
CVE-2025-0237P4MEDIUMCVSS 5.4fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0237 [MEDIUM] CWE-863 CVE-2025-0237: The WebChannel API, which is used to transport various information across processes, did not check t The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2006-6501P4MEDIUMCVSS 6.8fixed in 1.5.0.92006-12-20
CVE-2006-6501 [MEDIUM] CWE-264 CVE-2006-6501: Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird b Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
nvd
CVE-2008-0413P4CRITICALCVSS 9.3≤ 2.0.0.112008-02-08
CVE-2008-0413 [CRITICAL] CWE-399 CVE-2008-0413: The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2) certain uses of watch and eval, (3) certain uses of the mousedown event listener, and other vectors
nvd
CVE-2012-5354P4MEDIUMCVSS 6.8fixed in 16.02012-10-10
CVE-2012-5354 [MEDIUM] CVE-2012-5354: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly hand Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability tha
nvd
CVE-2015-7214P4MEDIUMCVSS 5.0≥ 0, < 1:38.5.1+build2-0ubuntu0.14.04.12015-12-15
CVE-2015-7214 [MEDIUM] CVE-2015-7214: Mozilla Firefox before 43 Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
osv
CVE-2013-1706P4HIGHCVSS 7.2≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1706 [HIGH] CWE-119 CVE-2013-1706: Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
nvd
CVE-2013-1707P4HIGHCVSS 7.2≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1707 [HIGH] CWE-119 CVE-2013-1707: Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x befo Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
nvd
CVE-2018-18494P4MEDIUMCVSS 6.5fixed in 60.4.0≥ unspecified, < 60.42019-02-28
CVE-2018-18494 [MEDIUM] CWE-346 CVE-2018-18494: A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascr A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvdosv
CVE-2020-12424P4MEDIUMCVSS 6.5≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12424 [MEDIUM] CVE-2020-12424: When constructing a permission prompt for WebRTC, a URI was supplied from the content process When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.
osv
CVE-2020-12425P4MEDIUMCVSS 6.5≥ 0, < 1:78.8.1+build1-0ubuntu0.18.04.1≥ 0, < 1:78.7.1+build1-0ubuntu0.20.04.12020-07-01
CVE-2020-12425 [MEDIUM] CVE-2020-12425: Due to confusion processing a hyphen character in Date Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
osv
CVE-2020-15652P4MEDIUMCVSS 6.5fixed in 68.11≥ 78.0, < 78.1+2 more2020-08-10
CVE-2020-15652 [MEDIUM] CWE-346 CVE-2020-15652: By observing the stack trace for JavaScript errors in web workers, it was possible to leak the resul By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
nvdosv
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-29945 [MEDIUM] CWE-682 CVE-2021-29945: The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read an The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvdosv
CVE-2019-5785P4MEDIUMCVSS 6.5≥ 0, < 1:60.5.1-12019-06-27
CVE-2019-5785 [MEDIUM] CVE-2019-5785: Incorrect convexity calculations in Skia in Google Chrome prior to 72 Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
osv
CVE-2006-1723P4HIGHCVSS 7.5v1.0v1.0.1+8 more2006-04-14
CVE-2006-1723 [HIGH] CVE-2006-1723: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvdosv
CVE-2006-2778P4MEDIUMCVSS 5.0≤ 1.5.0.32006-06-02
CVE-2006-2778 [MEDIUM] CVE-2006-2778: The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attacke The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.
nvdosv
CVE-2020-26961P4MEDIUMCVSS 6.5fixed in 78.52020-12-09
CVE-2020-26961 [MEDIUM] CVE-2020-26961: When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the respo When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR <
nvdosv
CVE-2021-38492P4MEDIUMCVSS 6.5fixed in 78.14≥ 91.0, < 91.1+2 more2021-11-03
CVE-2021-38492 [MEDIUM] CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which migh When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 7
nvd
CVE-2018-18499P4MEDIUMCVSS 6.5fixed in 60.2.1≥ unspecified, < 60.2.12019-02-28
CVE-2018-18499 [MEDIUM] CWE-346 CVE-2018-18499: A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase