Mozilla Thunderbird Esr vulnerabilities
228 known vulnerabilities affecting mozilla/thunderbird_esr.
Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1
Vulnerabilities
Page 7 of 12
CVE-2012-1948P3CRITICALCVSS 9.3v10.0v10.0.1+4 more2012-07-18
CVE-2012-1948 [CRITICAL] CVE-2012-1948: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Fire
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknow
nvd
CVE-2012-4183P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-4183 [CRITICAL] CWE-416 CVE-2012-4183: Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox bef
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified ve
nvd
CVE-2012-4181P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-4181 [CRITICAL] CWE-416 CVE-2012-4181: Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox
Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2012-5842P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-5842 [CRITICAL] CVE-2012-5842: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2012-4179P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-4179 [CRITICAL] CWE-416 CVE-2012-4179: Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox
Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecifie
nvd
CVE-2012-3982P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-3982 [CRITICAL] CVE-2012-3982: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-4182P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-4182 [CRITICAL] CWE-416 CVE-2012-4182: Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 1
Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors
nvd
CVE-2012-0472P3CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-04-25
CVE-2012-0472 [CRITICAL] CWE-119 CVE-2012-0472: The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4,
The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a
nvd
CVE-2013-1684P3CRITICALCVSS 9.3v17.0v17.0.1+5 more2013-06-26
CVE-2013-1684 [CRITICAL] CWE-399 CVE-2013-1684: Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable funct
Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted
nvd
CVE-2013-1685P3CRITICALCVSS 9.3v17.0v17.0.1+5 more2013-06-26
CVE-2013-1685 [CRITICAL] CWE-399 CVE-2013-1685: Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 2
Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site.
nvd
CVE-2013-1681P3CRITICALCVSS 10.0v17.0v17.0.1+4 more2013-05-16
CVE-2013-1681 [CRITICAL] CWE-399 CVE-2013-1681: Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox
Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1680P3CRITICALCVSS 10.0v17.0v17.0.1+4 more2013-05-16
CVE-2013-1680 [CRITICAL] CWE-119 CVE-2013-1680: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0,
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-0801P3CRITICALCVSS 10.0v17.0v17.0.1+4 more2013-05-16
CVE-2013-0801 [CRITICAL] CVE-2013-0801: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0788P3CRITICALCVSS 10.0v17.0v17.0.1+3 more2013-04-03
CVE-2013-0788 [CRITICAL] CVE-2013-0788: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2013-5591P3CRITICALCVSS 10.0v17.0.92013-10-30
CVE-2013-5591 [CRITICAL] CVE-2013-5591: Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-4217P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-4217 [CRITICAL] CWE-416 CVE-2012-4217: Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-4213P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-4213 [CRITICAL] CWE-416 CVE-2012-4213: Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17
Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-0770P3CRITICALCVSS 9.3fixed in 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0770 [CRITICAL] CVE-2013-0770: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-5843P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-5843 [CRITICAL] CVE-2012-5843: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0777P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0777 [CRITICAL] CWE-416 CVE-2013-0777: Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox befor
Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd