Mozilla Thunderbird Esr vulnerabilities
228 known vulnerabilities affecting mozilla/thunderbird_esr.
Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1
Vulnerabilities
Page 6 of 12
CVE-2013-0770CRITICALCVSS 9.3fixed in 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0770 [CRITICAL] CVE-2013-0770: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0763CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0763 [CRITICAL] CWE-416 CVE-2013-0763: Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunder
Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to Mesa drivers and a resized WebGL canvas.
nvd
CVE-2013-0769CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0769 [CRITICAL] CVE-2013-0769: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or po
nvd
CVE-2013-0752CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0752 [CRITICAL] CWE-119 CVE-2013-0752: Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird
Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XBL file with multiple bindings that have SVG content.
nvd
CVE-2013-0744CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0744 [CRITICAL] CWE-416 CVE-2013-0744: Use-after-free vulnerability in the TableBackgroundPainter::TableBackgroundData::Destroy function in
Use-after-free vulnerability in the TableBackgroundPainter::TableBackgroundData::Destroy function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or
nvd
CVE-2013-0760CRITICALCVSS 9.3fixed in 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0760 [CRITICAL] CWE-120 CVE-2013-0760: Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 18
Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2013-0762CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0762 [CRITICAL] CWE-416 CVE-2013-0762: Use-after-free vulnerability in the imgRequest::OnStopFrame function in Mozilla Firefox before 18.0,
Use-after-free vulnerability in the imgRequest::OnStopFrame function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (h
nvd
CVE-2013-0749CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0749 [CRITICAL] CVE-2013-0749: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2013-0761CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0761 [CRITICAL] CWE-416 CVE-2013-0761: Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Fi
Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via uns
nvd
CVE-2013-0767CRITICALCVSS 10.0≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0767 [CRITICAL] CWE-125 CVE-2013-0767: The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x b
The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read)
nvd
CVE-2013-0766CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0766 [CRITICAL] CWE-416 CVE-2013-0766: Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0,
Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (hea
nvd
CVE-2013-0745CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0745 [CRITICAL] CWE-94 CVE-2013-0745: The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunder
The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly interact with garbage collection, which allows remote attackers to execute arbitrary code via a crafted HTML document referencing JavaScript objects.
nvd
CVE-2013-0748MEDIUMCVSS 4.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0748 [MEDIUM] CWE-200 CVE-2013-0748: The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10
The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function
nvd
CVE-2013-0759MEDIUMCVSS 5.0≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0759 [MEDIUM] CWE-287 CVE-2013-0759: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to spoof the address bar via vectors involving authentication information in the userinfo field of a URL, in conjunction with a 204
nvd
CVE-2013-0747MEDIUMCVSS 6.8fixed in 17.0.22013-01-13
CVE-2013-0747 [MEDIUM] CWE-20 CVE-2013-0747: The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefo
The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly enforce the Same Origin Policy, which allows remote attackers to conduct clickjacking attacks via crafted JavaScript code
nvd
CVE-2012-5842CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-5842 [CRITICAL] CVE-2012-5842: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2012-4202CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-4202 [CRITICAL] CWE-787 CVE-2012-4202: Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before
Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.
nvd
CVE-2012-4215CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-4215 [CRITICAL] CWE-416 CVE-2012-4215: Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefo
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2012-5829CRITICALCVSS 9.3≥ 10.0, < 10.0.112012-11-21
CVE-2012-5829 [CRITICAL] CWE-787 CVE-2012-5829: Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, F
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4217CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-4217 [CRITICAL] CWE-416 CVE-2012-4217: Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd