Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 89 of 91
CVE-2006-1739CRITICALCVSS 9.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1739 [CRITICAL] CWE-119 CVE-2006-1739: The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0 The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer ove
nvdosv
CVE-2006-1728CRITICALCVSS 9.3≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1728 [CRITICAL] CVE-2006-1728: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0 Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
nvdosv
CVE-2006-0748CRITICALCVSS 9.3v1.0v1.0.1+8 more2006-04-14
CVE-2006-0748 [CRITICAL] CWE-399 CVE-2006-0748: Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7. Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.
nvdosv
CVE-2006-1726CRITICALCVSS 9.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1726 [CRITICAL] CWE-264 CVE-2006-1726: Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.
nvdosv
CVE-2006-0749CRITICALCVSS 9.3≥ 1.0, < 1.0.82006-04-14
CVE-2006-0749 [CRITICAL] CWE-399 CVE-2006-0749: nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozi nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.
nvdosv
CVE-2006-1790CRITICALCVSS 10.0≥ 0, < 1.5.0.2-12006-04-14
CVE-2006-1790 [CRITICAL] CVE-2006-1790: A regression fix in Mozilla Firefox 1 A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.
osv
CVE-2006-1724HIGHCVSS 7.5≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1724 [HIGH] CVE-2006-1724: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Sui Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.
nvdosv
CVE-2006-1529HIGHCVSS 7.5v1.0v1.0.1+8 more2006-04-14
CVE-2006-1529 [HIGH] CVE-2006-1529: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvdosv
CVE-2006-1530HIGHCVSS 7.5fixed in 1.5.0.22006-04-14
CVE-2006-1530 [HIGH] CVE-2006-1530: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvdosv
CVE-2006-1531HIGHCVSS 7.5fixed in 1.5.0.22006-04-14
CVE-2006-1531 [HIGH] CVE-2006-1531: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvdosv
CVE-2006-1727HIGHCVSS 7.6≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1727 [HIGH] CVE-2006-1727: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0 Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
nvdosv
CVE-2006-1723HIGHCVSS 7.5v1.0v1.0.1+8 more2006-04-14
CVE-2006-1723 [HIGH] CVE-2006-1723: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvdosv
CVE-2006-1733MEDIUMCVSS 6.8≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1733 [MEDIUM] CWE-264 CVE-2006-1733: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inse
nvdosv
CVE-2006-1732MEDIUMCVSS 4.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1732 [MEDIUM] CVE-2006-1732: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.
nvdosv
CVE-2006-1734MEDIUMCVSS 6.8≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1734 [MEDIUM] CVE-2006-1734: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.
nvdosv
CVE-2006-1738MEDIUMCVSS 5.0v1.0v1.0.1+7 more2006-04-14
CVE-2006-1738 [MEDIUM] CVE-2006-1738: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.
nvdosv
CVE-2006-1731MEDIUMCVSS 4.3≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1731 [MEDIUM] CWE-79 CVE-2006-1731: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
nvdosv
CVE-2006-1742MEDIUMCVSS 5.0≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1742 [MEDIUM] CVE-2006-1742: The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozi The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.
nvdosv
CVE-2006-1741MEDIUMCVSS 4.3≥ 0, < 1.5.0.2-12006-04-14
CVE-2006-1741 [MEDIUM] CVE-2006-1741: Mozilla Firefox 1 Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".
osv
CVE-2006-1740LOWCVSS 2.6≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1740 [LOW] CVE-2006-1740: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase