Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 79 of 91
CVE-2010-3768CRITICALCVSS 9.3≤ 3.0.10v0.1+76 more2010-12-10
CVE-2010-3768 [CRITICAL] CWE-20 CVE-2010-3768: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (
nvd
CVE-2010-3765CRITICALCVSS 9.8KEVPoCv3.0.1v3.0.2+12 more2010-10-28
CVE-2010-3765 [CRITICAL] CWE-119 CVE-2010-3765: Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the
nvd
CVE-2010-3183CRITICALCVSS 9.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3183 [CRITICAL] CWE-119 CVE-2010-3183: The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.
The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of servic
nvd
CVE-2010-3179CRITICALCVSS 9.3PoC≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3179 [CRITICAL] CWE-119 CVE-2010-3179: Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and
Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a long argument to the docum
nvd
CVE-2010-3176CRITICALCVSS 9.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3176 [CRITICAL] CVE-2010-3176: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3174CRITICALCVSS 9.3≤ 3.0.8v0.1+65 more2010-10-21
CVE-2010-3174 [CRITICAL] CVE-2010-3174: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3175CRITICALCVSS 9.3v3.1v3.1.1+3 more2010-10-21
CVE-2010-3175 [CRITICAL] CVE-2010-3175: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 and Thunderbird 3.1.x before 3.1.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3180CRITICALCVSS 9.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3180 [CRITICAL] CWE-399 CVE-2010-3180: Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x be
Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessing the locationbar property of a closed window.
nvd
CVE-2010-3173HIGHCVSS 7.5≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3173 [HIGH] CWE-310 CVE-2010-3173: The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack
nvd
CVE-2010-3182MEDIUMCVSS 6.9≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3182 [MEDIUM] CVE-2010-3182: A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
nvd
CVE-2010-3181MEDIUMCVSS 6.9≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3181 [MEDIUM] CVE-2010-3181: Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2010-3178MEDIUMCVSS 5.8≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3178 [MEDIUM] CWE-264 CVE-2010-3178: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers to bypass the Same Origin Policy vi
nvd
CVE-2010-3170MEDIUMCVSS 4.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3170 [MEDIUM] CWE-310 CVE-2010-3170: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Cert
nvd
CVE-2010-3166CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3166 [CRITICAL] CWE-119 CVE-2010-3166: Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before
Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.
nvd
CVE-2010-2766CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2766 [CRITICAL] CWE-94 CVE-2010-2766: The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
nvd
CVE-2010-2767CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2767 [CRITICAL] CWE-399 CVE-2010-2767: The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunde
The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via craft
nvd
CVE-2010-2765CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2765 [CRITICAL] CWE-189 CVE-2010-2765: Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x b
Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.
nvd
CVE-2010-3167CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3167 [CRITICAL] CWE-119 CVE-2010-3167: The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer v
nvd
CVE-2010-2770CRITICALCVSS 9.3≤ 3.0.6v0.1+68 more2010-09-09
CVE-2010-2770 [CRITICAL] CWE-119 CVE-2010-2770: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.
nvd
CVE-2010-3168CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3168 [CRITICAL] CWE-119 CVE-2010-3168: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary
nvd