VYPR

rpm package

opensuse/MozillaThunderbird&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweed

Vulnerabilities (1,666)

  • CVE-2022-1520MedDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A,

  • CVE-2022-0566HigDec 22, 2022
    affected < 91.6.1-1.1fixed 91.6.1-1.1

    It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.

  • CVE-2021-4140CriDec 22, 2022
    affected < 91.5.0-1.1fixed 91.5.0-1.1

    It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2021-4126MedDec 22, 2022
    affected < 91.4.1-1.1fixed 91.4.1-1.1

    When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression

  • CVE-2020-15685HigDec 22, 2022
    affected < 91.1.1-1.1fixed 91.1.1-1.1

    During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.

  • CVE-2022-39250HigSep 29, 2022
    affected < 102.3.1-1.1fixed 102.3.1-1.1

    Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identit

  • CVE-2022-39251HigSep 28, 2022
    affected < 102.3.1-1.1fixed 102.3.1-1.1

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Addit

  • CVE-2022-39249HigSep 28, 2022
    affected < 102.3.1-1.1fixed 102.3.1-1.1

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms,

  • CVE-2022-39236MedSep 28, 2022
    affected < 102.3.1-1.1fixed 102.3.1-1.1

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note th

  • CVE-2021-44538CriDec 14, 2021
    affected < 91.4.1-1.1fixed 91.4.1-1.1

    The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can cons

  • CVE-2021-43546MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43545MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43543MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43542MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43541MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43539HigDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird

  • CVE-2021-43538MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR <

  • CVE-2021-43537HigDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43536MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43528MedDec 8, 2021
    affected < 91.4.0-1.1fixed 91.4.0-1.1

    Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability af

Page 35 of 84