Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 94 of 101
CVE-2012-0474P4MEDIUMCVSS 4.3v5.0v6.0+13 more2012-04-25
CVE-2012-0474 [MEDIUM] CWE-79 CVE-2012-0474: Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x throu
Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Uni
nvd
CVE-2010-0654P4MEDIUMCVSS 4.3v3.0.1v3.0.2+4 more2010-02-18
CVE-2010-0654 [MEDIUM] CWE-200 CVE-2010-0654: Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information
nvd
CVE-2012-1944P4MEDIUMCVSS 4.3v5.0v6.0+14 more2012-06-05
CVE-2012-1944 [MEDIUM] CWE-79 CVE-2012-1944: The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTM
nvd
CVE-2013-1728P4MEDIUMCVSS 4.3≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1728 [MEDIUM] CWE-119 CVE-2013-1728: The IonMonkey JavaScript engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonk
The IonMonkey JavaScript engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21, when Valgrind mode is used, does not properly initialize memory, which makes it easier for remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-1559P4MEDIUMCVSS 4.3≤ 24.7v24.0+8 more2014-07-23
CVE-2014-1559 [MEDIUM] CVE-2014-1559: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
nvdosv
CVE-2013-1713P4MEDIUMCVSS 4.3≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1713 [MEDIUM] CWE-264 CVE-2013-1713: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons v
nvd
CVE-2010-2763P4MEDIUMCVSS 4.3≤ 3.0.6v0.1+63 more2010-09-09
CVE-2010-2763 [MEDIUM] CWE-79 CVE-2010-2763: The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Fir
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
nvd
CVE-2011-2366P4MEDIUMCVSS 4.3≤ 3.1.11v0.1+82 more2011-06-30
CVE-2011-2366 [MEDIUM] CWE-20 CVE-2011-2366: Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block u
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
nvd
CVE-2021-43546P4MEDIUMCVSS 4.3fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43546 [MEDIUM] CWE-1021 CVE-2021-43546: It was possible to recreate previous cursor spoofing attacks against users with a zoomed native curs
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
CVE-2015-2741P4MEDIUMCVSS 4.3≥ 0, < 1:31.8.0+build1-0ubuntu0.14.04.12015-07-05
CVE-2015-2741 [MEDIUM] CVE-2015-2741: Mozilla Firefox before 39
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.
osv
CVE-2006-0299P4MEDIUMCVSS 6.4v1.52006-02-02
CVE-2006-0299 [MEDIUM] CVE-2006-0299: The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in m
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
nvdosv
CVE-2021-23969P4MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23969 [MEDIUM] CVE-2021-23969: As specified in the W3C Content Security Policy draft, when creating a violation report, "User agent
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the s
nvdosv
CVE-2010-3170P4MEDIUMCVSS 4.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3170 [MEDIUM] CWE-310 CVE-2010-3170: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Cert
nvd
CVE-2021-23953P4MEDIUMCVSS 4.3fixed in 78.72021-02-26
CVE-2021-23953 [MEDIUM] CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cro
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvdosv
CVE-2013-0797P4MEDIUMCVSS 6.9v17.0v17.0.1+3 more2013-04-03
CVE-2013-0797 [MEDIUM] CVE-2013-0797: Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox E
Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allows local users to gain privileges via a Trojan horse DLL file in an unspecified directory.
nvd
CVE-2015-0833P4MEDIUMCVSS 6.9≤ 31.4v31.0+3 more2015-02-25
CVE-2015-0833 [MEDIUM] CVE-2015-0833: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefo
Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dl
nvd
CVE-2022-26383P4MEDIUMCVSS 4.3fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26383 [MEDIUM] CWE-451 CVE-2022-26383: When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvdosv
CVE-2023-32212P4MEDIUMCVSS 4.3fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32212 [MEDIUM] CVE-2023-32212: An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerabilit
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdosv
CVE-2023-32205P4MEDIUMCVSS 4.3fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32205 [MEDIUM] CVE-2023-32205: In multiple cases browser prompts could have been obscured by popups controlled by content. These co
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdosv
CVE-2023-5726P4MEDIUMCVSS 4.3fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5726 [MEDIUM] CVE-2023-5726: A website could have obscured the full screen notification by using the file open dialog. This could
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks.
*Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv