Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 99 of 101
CVE-2004-0761P4MEDIUMCVSS 5.0≤ 0.72004-08-18
CVE-2004-0761 [MEDIUM] CVE-2004-0761: Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use ce
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.
nvd
CVE-2010-2754P4MEDIUMCVSS 5.0v3.0v3.0.1+5 more2010-07-30
CVE-2010-2754 [MEDIUM] CWE-200 CVE-2010-2754: dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderb
dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about s
nvd
CVE-2006-4568P4MEDIUMCVSS 4.3≥ 0, < 1.5.0.7-12006-09-15
CVE-2006-4568 [MEDIUM] CVE-2006-4568: Mozilla Firefox before 1
Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.
osv
CVE-2011-3663P4MEDIUMCVSS 4.3v5.0v6.0+4 more2011-12-21
CVE-2011-3663 [MEDIUM] CWE-200 CVE-2011-3663: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
nvd
CVE-2014-1590P4MEDIUMCVSS 4.3≤ 31.22014-12-11
CVE-2014-1590 [MEDIUM] CWE-20 CVE-2014-1590: The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.
The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.
nvdosv
CVE-2008-6961P4MEDIUMCVSS 4.3≤ 2.0.0.17v0.1+55 more2009-08-13
CVE-2008-6961 [MEDIUM] CWE-200 CVE-2008-6961: mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enab
mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
nvd
CVE-2010-1207P4MEDIUMCVSS 4.3≤ 3.12010-07-30
CVE-2010-1207 [MEDIUM] CWE-264 CVE-2010-1207: Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restriction
Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.
nvd
CVE-2008-2808P4MEDIUMCVSS 4.3v2.0_.4v2.0_.5+6 more2008-07-07
CVE-2008-2808 [MEDIUM] CWE-79 CVE-2008-2808: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// U
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.
nvd
CVE-2010-1210P4MEDIUMCVSS 4.3≤ 3.1v0.1+69 more2010-07-30
CVE-2010-1210 [MEDIUM] CWE-20 CVE-2010-1210: intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1
intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.
nvd
CVE-2013-0774P4MEDIUMCVSS 4.3fixed in 17.0.32013-02-19
CVE-2013-0774 [MEDIUM] CVE-2013-0774: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile directory name, which has unspecified impact and remote attack vectors.
nvd
CVE-2010-1213P4MEDIUMCVSS 4.3v3.0v3.0.1+5 more2010-07-30
CVE-2010-1213 [MEDIUM] CWE-20 CVE-2010-1213: The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, T
The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML doc
nvd
CVE-2010-5074P4MEDIUMCVSS 4.3≤ 3.1.16v3.0+27 more2011-12-07
CVE-2010-5074 [MEDIUM] CWE-362 CVE-2010-5074: The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 ex
The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack.
nvd
CVE-2019-11743P4LOWCVSS 3.7fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11743 [LOW] CWE-203 CVE-2019-11743: Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specificati
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affect
nvdosv
CVE-2025-0239P4MEDIUMCVSS 4.0fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0239 [MEDIUM] CWE-295 CVE-2025-0239: When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirect
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2024-3302P4LOWCVSS 3.7≤ 115.10≥ unspecified, < 115.102024-04-16
CVE-2024-3302 [LOW] CWE-770 CVE-2024-3302: There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server cou
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2007-5339P4MEDIUMCVSS 4.3≤ 2.0.0.62007-10-21
CVE-2007-5339 [MEDIUM] CWE-20 CVE-2007-5339: Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonke
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
nvd
CVE-2007-5340P4MEDIUMCVSS 4.3≤ 2.0.0.62007-10-21
CVE-2007-5340 [MEDIUM] CWE-20 CVE-2007-5340: Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird bef
Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.
nvd
CVE-2006-1732P4MEDIUMCVSS 4.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1732 [MEDIUM] CVE-2006-1732: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8,
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.
nvdosv
CVE-2006-1731P4MEDIUMCVSS 4.3≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1731 [MEDIUM] CWE-79 CVE-2006-1731: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13,
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
nvdosv
CVE-2004-0906P4MEDIUMCVSS 4.6v0.1v0.2+8 more2004-12-31
CVE-2004-0906 [MEDIUM] CVE-2004-0906: The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thu
The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.
nvd