cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 91 of 101
CVE-2021-38508P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38508 [MEDIUM] CWE-1021 CVE-2021-38508: By displaying a form validity message in the correct location at the same time as a permission promp By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2024-1548P4MEDIUMCVSS 4.3fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1548 [MEDIUM] CVE-2024-1548: A website could have obscured the fullscreen notification by using a dropdown select input element. A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvdosv
CVE-2023-5725P4MEDIUMCVSS 4.3fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5725 [MEDIUM] CVE-2023-5725: A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance cou A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2013-1712P4MEDIUMCVSS 6.9≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1712 [MEDIUM] CVE-2013-1712: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update
nvd
CVE-2012-3974P4MEDIUMCVSS 6.9≤ 14.0v1.0+100 more2012-08-29
CVE-2012-3974 [MEDIUM] CWE-399 CVE-2012-3974: Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10. Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.
nvd
CVE-2024-5690P4MEDIUMCVSS 4.3fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5690 [MEDIUM] CWE-203 CVE-2024-5690: By monitoring the time certain operations take, an attacker could have guessed which external protoc By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvdosv
CVE-2024-11692P4MEDIUMCVSS 4.3fixed in 128.5≥ 129.0, < 133.0+2 more2024-11-26
CVE-2024-11692 [MEDIUM] CWE-290 CVE-2024-11692: An attacker could cause a select dropdown to be shown over another tab; this could have led to user An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvdosv
CVE-2006-1738P4MEDIUMCVSS 5.0v1.0v1.0.1+7 more2006-04-14
CVE-2006-1738 [MEDIUM] CVE-2006-1738: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.
nvdosv
CVE-2006-4566P4MEDIUMCVSS 5.0≤ 1.5.0.62006-09-15
CVE-2006-4566 [MEDIUM] CVE-2006-4566: Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.
nvdosv
CVE-2009-0777P4MEDIUMCVSS 5.8≤ 2.0.0.20v2.0.0.0+10 more2009-03-05
CVE-2009-0777 [MEDIUM] CWE-20 CVE-2009-0777: Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisi Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
nvd
CVE-2009-1302P4MEDIUMCVSS 5.0≤ 2.0.0.19v1.0+37 more2009-04-22
CVE-2009-1302 [MEDIUM] CWE-399 CVE-2009-1302: The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey b The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the
nvd
CVE-2011-3670P4MEDIUMCVSS 5.0≤ 3.1.7v0.1+86 more2012-02-01
CVE-2011-3670 [MEDIUM] CWE-200 CVE-2011-3670: Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, an Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages.
nvd
CVE-2006-1741P4MEDIUMCVSS 4.3≥ 0, < 1.5.0.2-12006-04-14
CVE-2006-1741 [MEDIUM] CVE-2006-1741: Mozilla Firefox 1 Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".
osv
CVE-2010-0169P4MEDIUMCVSS 5.0≤ 3.0.1v1.5+30 more2010-03-25
CVE-2010-0169 [MEDIUM] CVE-2010-0169: The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the
nvd
CVE-2005-0149P4MEDIUMCVSS 5.0v0.6v0.7+4 more2005-02-15
CVE-2005-0149 [MEDIUM] CVE-2005-0149: Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCo Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
nvd
CVE-2014-1496P4MEDIUMCVSS 5.5fixed in 24.42014-03-19
CVE-2014-1496 [MEDIUM] CWE-269 CVE-2014-1496: Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey be Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
nvd
CVE-2012-4207P4MEDIUMCVSS 4.3fixed in 17.02012-11-21
CVE-2012-4207 [MEDIUM] CWE-79 CVE-2012-4207: The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2020-16012P4MEDIUMCVSS 4.3≥ 0, < 1:78.5.0-12021-01-08
CVE-2020-16012 [MEDIUM] CVE-2020-16012: Side-channel information leakage in graphics in Google Chrome prior to 87 Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
osv
CVE-2012-0479P4MEDIUMCVSS 4.3v5.0v6.0+13 more2012-04-25
CVE-2012-0479 [MEDIUM] CVE-2012-0479: Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thun Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.
nvd
CVE-2008-5508P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.192008-12-17
CVE-2008-5508 [MEDIUM] CWE-20 CVE-2008-5508: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.
nvd