Mozilla Thunderbird Esr vulnerabilities
228 known vulnerabilities affecting mozilla/thunderbird_esr.
Total CVEs
228
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL144HIGH16MEDIUM67LOW1
Vulnerabilities
Page 9 of 12
CVE-2012-0463P4HIGHCVSS 7.5v10.0v10.0.1+1 more2012-03-14
CVE-2012-0463 [HIGH] CWE-20 CVE-2012-0463: The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 1
The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a d
nvd
CVE-2012-0461P4HIGHCVSS 7.5v10.0v10.0.1+1 more2012-03-14
CVE-2012-0461 [HIGH] CVE-2012-0461: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe
nvd
CVE-2012-4196P4MEDIUMCVSS 6.4≥ 10.0, < 10.0.102012-10-29
CVE-2012-4196 [MEDIUM] CWE-74 CVE-2012-4196: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
nvd
CVE-2012-0454P4HIGHCVSS 7.5v10.0v10.0.1+1 more2012-03-14
CVE-2012-0454 [HIGH] CWE-399 CVE-2012-0454: Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of
nvd
CVE-2012-0458P4MEDIUMCVSS 6.8v10.0v10.0.1+1 more2012-03-14
CVE-2012-0458 [MEDIUM] CWE-264 CVE-2012-0458: Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird befo
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrar
nvd
CVE-2012-3978P4MEDIUMCVSS 6.8v10.0v10.0.1+5 more2012-08-29
CVE-2012-3978 [MEDIUM] CWE-264 CVE-2012-3978: The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Th
The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspe
nvd
CVE-2013-5596P4MEDIUMCVSS 6.8v17.0.92013-10-30
CVE-2013-5596 [MEDIUM] CWE-119 CVE-2013-5596: The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.
The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attackers to execute arbitrary code or cause a denial of service (race condition and application crash) via
nvd
CVE-2012-1955P4MEDIUMCVSS 6.8v10.0v10.0.1+4 more2012-07-18
CVE-2012-1955 [MEDIUM] CVE-2012-1955: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to spoof the address bar via vectors involving history.forward and history.back calls.
nvd
CVE-2013-1730P4MEDIUMCVSS 6.8v17.0v17.0.1+7 more2013-09-18
CVE-2013-1730 [MEDIUM] CWE-119 CVE-2013-1730: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion fa
nvd
CVE-2012-4193P4MEDIUMCVSS 6.8≥ 10.0, < 10.0.92012-10-12
CVE-2012-4193 [MEDIUM] CWE-346 CVE-2012-4193: Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbir
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location obj
nvd
CVE-2013-1706P4HIGHCVSS 7.2v17.0v17.0.1+6 more2013-08-07
CVE-2013-1706 [HIGH] CWE-119 CVE-2013-1706: Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla
Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
nvd
CVE-2013-1707P4HIGHCVSS 7.2v17.0v17.0.1+6 more2013-08-07
CVE-2013-1707 [HIGH] CWE-119 CVE-2013-1707: Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x befo
Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
nvd
CVE-2013-1717P4MEDIUMCVSS 5.4v17.0v17.0.1+6 more2013-08-07
CVE-2013-1717 [MEDIUM] CWE-264 CVE-2013-1717: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable path
nvd
CVE-2013-0747P4MEDIUMCVSS 6.8fixed in 17.0.22013-01-13
CVE-2013-0747 [MEDIUM] CWE-20 CVE-2013-0747: The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefo
The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly enforce the Same Origin Policy, which allows remote attackers to conduct clickjacking attacks via crafted JavaScript code
nvd
CVE-2012-0460P4MEDIUMCVSS 6.4v10.0v10.0.1+1 more2012-03-14
CVE-2012-0460 [MEDIUM] CWE-264 CVE-2012-0460: Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thun
Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.
nvd
CVE-2018-5185P4MEDIUMCVSS 6.5fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5185 [MEDIUM] CWE-311 CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerabili
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2013-0799P4HIGHCVSS 7.2v17.0v17.0.1+3 more2013-04-03
CVE-2013-0799 [HIGH] CWE-119 CVE-2013-0799: Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x
Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain privileges via crafted arguments.
nvd
CVE-2013-0791P4MEDIUMCVSS 5.0≥ 17.0, < 17.0.52013-04-03
CVE-2013-0791 [MEDIUM] CWE-119 CVE-2013-0791: The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla F
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption)
nvd
CVE-2018-5168P4MEDIUMCVSS 5.3fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvd
CVE-2013-0759P4MEDIUMCVSS 5.0≥ 10.0, < 10.0.12≥ 17.0, < 17.0.22013-01-13
CVE-2013-0759 [MEDIUM] CWE-287 CVE-2013-0759: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to spoof the address bar via vectors involving authentication information in the userinfo field of a URL, in conjunction with a 204
nvd