Mozilla Thunderbird Esr vulnerabilities
228 known vulnerabilities affecting mozilla/thunderbird_esr.
Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1
Vulnerabilities
Page 11 of 12
CVE-2012-5841P4MEDIUMCVSS 4.3fixed in 10.0.112012-11-21
CVE-2012-5841 [MEDIUM] CWE-79 CVE-2012-5841: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
nvd
CVE-2012-4195P4MEDIUMCVSS 4.3fixed in 10.0.102012-10-29
CVE-2012-4195 [MEDIUM] CWE-79 CVE-2012-4195: The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10,
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (X
nvd
CVE-2013-1672P4MEDIUMCVSS 6.9≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1672 [MEDIUM] CWE-264 CVE-2013-1672: The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thun
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
nvd
CVE-2013-1726P4MEDIUMCVSS 6.2v17.0v17.0.1+7 more2013-09-18
CVE-2013-1726 [MEDIUM] CWE-264 CVE-2013-1726: Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 2
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
nvd
CVE-2012-3992P4MEDIUMCVSS 4.3fixed in 10.0.82012-10-10
CVE-2012-3992 [MEDIUM] CWE-79 CVE-2012-3992: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and hi
nvd
CVE-2012-0451P4MEDIUMCVSS 4.3v10.0v10.0.1+1 more2012-03-14
CVE-2012-0451 [MEDIUM] CWE-94 CVE-2012-0451: CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP head
nvd
CVE-2013-0793P4MEDIUMCVSS 4.3v17.0v17.0.1+3 more2013-04-03
CVE-2013-0793 [MEDIUM] CWE-79 CVE-2013-0793: Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird
Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over naviga
nvd
CVE-2012-1961P4MEDIUMCVSS 4.3v10.0v10.0.1+4 more2012-07-18
CVE-2012-1961 [MEDIUM] CWE-20 CVE-2012-1961: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly handle duplicate values in X-Frame-Options headers, which makes it easier for remote attackers to conduct clickjacking attacks via a FRAME element referencing a web site that produ
nvd
CVE-2013-1714P4MEDIUMCVSS 4.3v17.0v17.0.1+6 more2013-08-07
CVE-2013-1714 [MEDIUM] CWE-264 CVE-2013-1714: The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thund
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspec
nvd
CVE-2012-1957P4MEDIUMCVSS 4.3v10.0v10.0.1+4 more2012-07-18
CVE-2012-1957 [MEDIUM] CWE-79 CVE-2012-1957: An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.
An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly handle EMBED elements within description elements in RSS feeds, which allows remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2013-1692P4MEDIUMCVSS 4.3v17.0v17.0.1+5 more2013-06-26
CVE-2013-1692 [MEDIUM] CWE-264 CVE-2013-1692: Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderb
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.
nvd
CVE-2014-2018P4MEDIUMCVSS 4.3v17.0v17.0.1+8 more2014-02-17
CVE-2014-2018 [MEDIUM] CVE-2014-2018: Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in a (1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.
nvd
CVE-2012-0474P4MEDIUMCVSS 4.3v10.0v10.0.1+2 more2012-04-25
CVE-2012-0474 [MEDIUM] CWE-79 CVE-2012-0474: Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x throu
Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Uni
nvd
CVE-2012-1944P4MEDIUMCVSS 4.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1944 [MEDIUM] CWE-79 CVE-2012-1944: The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTM
nvd
CVE-2013-1713P4MEDIUMCVSS 4.3v17.0v17.0.1+6 more2013-08-07
CVE-2013-1713 [MEDIUM] CWE-264 CVE-2013-1713: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons v
nvd
CVE-2013-0797P4MEDIUMCVSS 6.9v17.0v17.0.1+3 more2013-04-03
CVE-2013-0797 [MEDIUM] CVE-2013-0797: Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox E
Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allows local users to gain privileges via a Trojan horse DLL file in an unspecified directory.
nvd
CVE-2012-4194P4MEDIUMCVSS 4.3≥ 10.0, < 10.0.102012-10-29
CVE-2012-4194 [MEDIUM] CWE-79 CVE-2012-4194: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors inv
nvd
CVE-2012-4209P4MEDIUMCVSS 4.3≥ 10.0, < 10.0.112012-11-21
CVE-2012-4209 [MEDIUM] CWE-79 CVE-2012-4209: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a b
nvd
CVE-2012-3994P4MEDIUMCVSS 4.3fixed in 10.0.82012-10-10
CVE-2012-3994 [MEDIUM] CWE-79 CVE-2012-3994: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the
nvd
CVE-2018-5161P4MEDIUMCVSS 4.3fixed in 52.8≥ unspecified, < 52.82018-06-11
CVE-2018-5161 [MEDIUM] CWE-20 CVE-2018-5161: Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulne
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd