cbcvebase.

Mozilla Thunderbird Esr vulnerabilities

228 known vulnerabilities affecting mozilla/thunderbird_esr.

Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1

Vulnerabilities

Page 2 of 12
CVE-2012-3963P3CRITICALCVSS 10.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3963 [CRITICAL] CWE-416 CVE-2012-3963: Use-after-free vulnerability in the js::gc::MapAllocToTraceKind function in Mozilla Firefox before 1 Use-after-free vulnerability in the js::gc::MapAllocToTraceKind function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-5600P3CRITICALCVSS 10.0v17.0.9v17.0+8 more2013-10-30
CVE-2013-5600 [CRITICAL] CVE-2013-5600: Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code via vectors involving a blob: URL.
nvd
CVE-2013-5601P3CRITICALCVSS 10.0v17.0.9v17.0+8 more2013-10-30
CVE-2013-5601 [CRITICAL] CVE-2013-5601: Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Fire Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code via vectors related to a memory allocation through
nvd
CVE-2012-5839P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-5839 [CRITICAL] CWE-787 CVE-2012-5839: Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-0754P3CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0754 [CRITICAL] CWE-416 CVE-2013-0754: Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, F Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors involving the trigger
nvd
CVE-2012-1941P3CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1941 [CRITICAL] CWE-119 CVE-2012-1941: Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Fi Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code by resizing a window displaying absolutely positioned
nvd
CVE-2012-1947P3CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1947 [CRITICAL] CWE-119 CVE-2012-1947: Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, F Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.
nvd
CVE-2013-0787P3CRITICALCVSS 9.3v17.0v17.0.1+2 more2013-03-11
CVE-2013-0787 [CRITICAL] CWE-399 CVE-2013-0787: Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEdi Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand
nvd
CVE-2012-4185P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-4185 [CRITICAL] CWE-119 CVE-2012-4185: Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10. Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-0768P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0768 [CRITICAL] CWE-787 CVE-2013-0768: Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via an HTML document that specifies invalid width and height values.
nvd
CVE-2013-0750P3CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0750 [CRITICAL] CWE-190 CVE-2013-0750: Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x b Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted string concatenation, leading to imp
nvd
CVE-2013-6674P4MEDIUMCVSS 4.3PoCv17.0v17.0.1+9 more2014-02-17
CVE-2013-6674 [MEDIUM] CWE-79 CVE-2013-6674: Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.
nvd
CVE-2012-0470P3CRITICALCVSS 10.0v10.0v10.0.1+3 more2012-04-25
CVE-2012-0470 [CRITICAL] CWE-119 CVE-2012-0470: Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Fire Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly
nvd
CVE-2012-3990P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-3990 [CRITICAL] CWE-416 CVE-2012-3990: Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the nsIContent::GetNameSpaceID function.
nvd
CVE-2013-1735P3CRITICALCVSS 9.3v17.0v17.0.1+7 more2013-09-18
CVE-2013-1735 [CRITICAL] CWE-20 CVE-2013-1735: Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox b Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.
nvd
CVE-2012-3962P3CRITICALCVSS 9.3v10.0v10.0.1+5 more2012-08-29
CVE-2012-3962 [CRITICAL] CVE-2012-3962: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ES Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2012-5835P3CRITICALCVSS 10.0fixed in 10.0.112012-11-21
CVE-2012-5835 [CRITICAL] CWE-190 CVE-2012-5835: Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0 Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via crafted data.
nvd
CVE-2012-3966P3CRITICALCVSS 10.0v10.0v10.0.1+5 more2012-08-29
CVE-2012-3966 [CRITICAL] CWE-119 CVE-2012-3966: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ES Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a negative height value in a BMP image within a .ICO file, related to (1) improper handling of the tr
nvd
CVE-2013-5604P3CRITICALCVSS 9.3v17.0v17.0.1+8 more2013-10-30
CVE-2013-5604 [CRITICAL] CWE-119 CVE-2013-5604: The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Fire The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of s
nvd
CVE-2013-0782P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0782 [CRITICAL] CWE-787 CVE-2013-0782: Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox b Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
Mozilla Thunderbird Esr vulnerabilities | cvebase