Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 96 of 101
CVE-2012-1956P4MEDIUMCVSS 4.3≤ 14.0v1.0+98 more2012-08-29
CVE-2012-1956 [MEDIUM] CWE-79 CVE-2012-1956: Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use o
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
nvd
CVE-2012-0455P4MEDIUMCVSS 4.3≤ 3.1.19v5.0+6 more2012-03-14
CVE-2012-0455 [MEDIUM] CWE-79 CVE-2012-0455: Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird befo
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2017-7847P4MEDIUMCVSS 4.3fixed in 52.5.2≥ unspecified, < 52.5.22018-06-11
CVE-2017-7847 [MEDIUM] CWE-200 CVE-2017-7847: Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
nvdosv
CVE-2018-18511P4MEDIUMCVSS 4.3≥ 0, < 1:60.7.0-12019-04-26
CVE-2018-18511 [MEDIUM] CVE-2018-18511: Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
osv
CVE-2012-0446P4MEDIUMCVSS 4.3v5.0v6.0+5 more2012-02-01
CVE-2012-0446 [MEDIUM] CWE-79 CVE-2012-0446: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted o
nvd
CVE-2011-2983P4MEDIUMCVSS 4.3v2.0v2.0.0.0+46 more2011-08-18
CVE-2011-2983 [MEDIUM] CWE-200 CVE-2011-2983: Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and pos
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.
nvd
CVE-2017-5451P4MEDIUMCVSS 4.3fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5451 [MEDIUM] CWE-20 CVE-2017-5451: A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur"
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2013-1709P4MEDIUMCVSS 4.3≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1709 [MEDIUM] CWE-79 CVE-2013-1709: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in
nvd
CVE-2010-0182P4MEDIUMCVSS 4.3≤ 3.0.3v0.1+59 more2010-04-05
CVE-2010-0182 [MEDIUM] CWE-20 CVE-2010-0182: The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird b
The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.
nvd
CVE-2014-1558P4MEDIUMCVSS 4.3≤ 24.7v24.0+8 more2014-07-23
CVE-2014-1558 [MEDIUM] CVE-2014-1558: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1559.
nvdosv
CVE-2011-2605P4MEDIUMCVSS 4.3≤ 3.1.10v0.1+81 more2011-06-30
CVE-2011-2605 [MEDIUM] CVE-2011-2605: CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/coo
CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a Ja
nvd
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2012-1943P4MEDIUMCVSS 6.9v12.02012-06-05
CVE-2012-1943 [MEDIUM] CVE-2012-1943: Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox
Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.
nvd
CVE-2010-3181P4MEDIUMCVSS 6.9≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3181 [MEDIUM] CVE-2010-3181: Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2022-46877P4MEDIUMCVSS 4.3≥ 0, < 1:102.8.0-1~deb11u1≥ 0, < 1:102.7.1-12022-12-22
CVE-2022-46877 [MEDIUM] CVE-2022-46877: By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks
By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.
osv
CVE-2023-50762P4MEDIUMCVSS 4.3fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-50762 [MEDIUM] CVE-2023-50762: When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the t
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to
nvdosv
CVE-2023-50761P4MEDIUMCVSS 4.3fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-50761 [MEDIUM] CVE-2023-50761: The signature of a digitally signed S/MIME email message may optionally specify the signature creati
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent
nvdosv
CVE-2021-23992P4MEDIUMCVSS 4.3fixed in 78.9.1≥ unspecified, < 78.9.12021-06-24
CVE-2021-23992 [MEDIUM] CWE-347 CVE-2021-23992: Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature.
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID bel
nvdosv
CVE-2024-6608P4MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6608 [MEDIUM] CVE-2024-6608: It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2024-6614P4MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6614 [MEDIUM] CWE-835 CVE-2024-6614: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd