cbcvebase.

Mozilla Thunderbird Esr vulnerabilities

228 known vulnerabilities affecting mozilla/thunderbird_esr.

Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1

Vulnerabilities

Page 6 of 12
CVE-2012-1962P3CRITICALCVSS 10.0v10.0v10.0.1+4 more2012-07-18
CVE-2012-1962 [CRITICAL] CWE-399 CVE-2012-1962: Use-after-free vulnerability in the JSDependentString::undepend function in Mozilla Firefox 4.x thro Use-after-free vulnerability in the JSDependentString::undepend function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vecto
nvd
CVE-2012-1970P3CRITICALCVSS 10.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-1970 [CRITICAL] CWE-119 CVE-2012-1970: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown
nvd
CVE-2013-1718P3CRITICALCVSS 10.0v17.0v17.0.1+7 more2013-09-18
CVE-2013-1718 [CRITICAL] CWE-119 CVE-2013-1718: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown
nvd
CVE-2013-5599P3CRITICALCVSS 10.0v17.0v17.0.1+8 more2013-10-30
CVE-2013-5599 [CRITICAL] CVE-2013-5599: Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka pres Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or c
nvd
CVE-2012-1954P3CRITICALCVSS 10.0v10.0v10.0.1+4 more2012-07-18
CVE-2012-1954 [CRITICAL] CWE-399 CVE-2012-1954: Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13 Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vector
nvd
CVE-2012-4215P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-4215 [CRITICAL] CWE-416 CVE-2012-4215: Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefo Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2012-5840P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-5840 [CRITICAL] CVE-2012-5840: Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox bef Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors,
nvd
CVE-2012-4216P3CRITICALCVSS 9.3≥ 10.0, < 10.0.112012-11-21
CVE-2012-4216 [CRITICAL] CWE-416 CVE-2012-4216: Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, F Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-4214P3CRITICALCVSS 9.3≥ 10.0, < 10.0.112012-11-21
CVE-2012-4214 [CRITICAL] CWE-416 CVE-2012-4214: Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox bef Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2012-3995P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-3995 [CRITICAL] CWE-125 CVE-2012-3995: The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, T The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-1937P3CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1937 [CRITICAL] CVE-2012-1937: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 12.0, Fire Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknow
nvd
CVE-2018-5183P3CRITICALCVSS 9.8fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5183 [CRITICAL] CWE-119 CVE-2018-5183: Mozilla developers backported selected changes in the Skia library. These changes correct memory cor Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd
CVE-2013-0780P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0780 [CRITICAL] CWE-416 CVE-2013-0780: Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefo Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a craft
nvd
CVE-2013-1697P3CRITICALCVSS 9.3v17.0v17.0.1+5 more2013-06-26
CVE-2013-1697 [CRITICAL] CWE-264 CVE-2013-1697: The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thund The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that trigger
nvd
CVE-2013-1679P3CRITICALCVSS 10.0v17.0v17.0.1+4 more2013-05-16
CVE-2013-1679 [CRITICAL] CWE-399 CVE-2013-1679: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firef Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-5603P3CRITICALCVSS 10.0v17.0.92013-10-30
CVE-2013-5603 [CRITICAL] CVE-2013-5603: Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in M Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
nvd
CVE-2013-1686P3CRITICALCVSS 10.0v17.0v17.0.1+5 more2013-06-26
CVE-2013-1686 [CRITICAL] CWE-399 CVE-2013-1686: Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firef Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1682P3CRITICALCVSS 10.0v17.0v17.0.1+5 more2013-06-26
CVE-2013-1682 [CRITICAL] CVE-2013-1682: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-1701P3CRITICALCVSS 10.0v17.0v17.0.1+6 more2013-08-07
CVE-2013-1701 [CRITICAL] CVE-2013-1701: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2013-1722P3CRITICALCVSS 9.3v17.0v17.0.1+7 more2013-09-18
CVE-2013-1722 [CRITICAL] CWE-399 CVE-2013-1722: Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Ma Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory co
nvd