Mozilla Thunderbird Esr vulnerabilities
228 known vulnerabilities affecting mozilla/thunderbird_esr.
Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1
Vulnerabilities
Page 8 of 12
CVE-2012-5833P3CRITICALCVSS 9.3fixed in 10.0.112012-11-21
CVE-2012-5833 [CRITICAL] CWE-119 CVE-2012-5833: The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup
nvd
CVE-2013-0784P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0784 [CRITICAL] CVE-2013-0784: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0763P3CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0763 [CRITICAL] CWE-416 CVE-2013-0763: Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunder
Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to Mesa drivers and a resized WebGL canvas.
nvd
CVE-2013-0761P3CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0761 [CRITICAL] CWE-416 CVE-2013-0761: Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Fi
Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via uns
nvd
CVE-2013-0781P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0781 [CRITICAL] CWE-416 CVE-2013-0781: Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19
Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-0800P3MEDIUMCVSS 6.8≥ 17.0, < 17.0.52013-04-03
CVE-2013-0800 [MEDIUM] CVE-2013-0800: Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed
Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values t
nvd
CVE-2012-3105P3CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-3105 [CRITICAL] CVE-2012-3105: The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox E
The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruptio
nvd
CVE-2018-5162P3HIGHCVSS 7.5fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5162 [HIGH] CWE-311 CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vu
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2013-1694P3HIGHCVSS 7.5v17.0v17.0.1+5 more2013-06-26
CVE-2013-1694 [HIGH] CWE-20 CVE-2013-1694: The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, T
The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly handle the lack of a wrapper, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by leveraging unintended clea
nvd
CVE-2013-0749P3CRITICALCVSS 9.3≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0749 [CRITICAL] CVE-2013-0749: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2012-1940P3CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1940 [CRITICAL] CWE-399 CVE-2012-1940: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application cra
nvd
CVE-2013-1725P3MEDIUMCVSS 6.8v17.0v17.0.1+7 more2013-09-18
CVE-2013-1725 [MEDIUM] CWE-119 CVE-2013-1725: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.
nvd
CVE-2013-1687P3CRITICALCVSS 9.3v17.0v17.0.1+5 more2013-06-26
CVE-2013-1687 [CRITICAL] CWE-264 CVE-2013-1687: The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox bef
The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly restrict XBL user-defined functions, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges,
nvd
CVE-2018-5184P3HIGHCVSS 7.5fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5184 [HIGH] CWE-326 CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerabili
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2012-3991P3CRITICALCVSS 9.3fixed in 10.0.82012-10-10
CVE-2012-3991 [CRITICAL] CWE-264 CVE-2012-3991: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.
nvd
CVE-2013-0773P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0773 [CRITICAL] CVE-2013-0773: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox bef
The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects o
nvd
CVE-2013-0783P4CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0783 [CRITICAL] CVE-2013-0783: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2012-1939P4CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1939 [CRITICAL] CWE-119 CVE-2012-1939: jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does no
jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does not properly determine data types, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted JavaScript code.
nvd
CVE-2012-0459P4HIGHCVSS 7.5v10.0v10.0.1+1 more2012-03-14
CVE-2012-0459 [HIGH] CWE-264 CVE-2012-0459: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via dynamic modification of a keyframe
nvd
CVE-2012-0462P4HIGHCVSS 7.5v10.0v10.0.1+1 more2012-03-14
CVE-2012-0462 [HIGH] CVE-2012-0462: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Fire
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vec
nvd