VYPR

Thunderbird

by Mozilla Corporation

Source repositories

CVEs (2,087)

  • CVE-2024-8900HigSep 17, 2024
    risk 0.49cvss 7.5epss 0.00

    An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.

  • CVE-2024-7652HigSep 6, 2024
    risk 0.49cvss 7.5epss 0.01

    An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird <…

  • CVE-2024-6604HigJul 9, 2024
    risk 0.49cvss 7.5epss 0.01

    Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox…

  • CVE-2024-5702HigJun 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.

  • CVE-2024-3852HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2024-1936HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.01

    The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a…

  • CVE-2024-1552HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • CVE-2024-1546HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.01

    When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • CVE-2024-0743HigJan 23, 2024
    risk 0.49cvss 7.5epss 0.01

    An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2023-5728HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-5724HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.02

    Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-4583HigSep 11, 2023
    risk 0.49cvss 7.5epss 0.01

    When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability…

  • CVE-2023-4051HigAug 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

  • CVE-2023-3417HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.01

    Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file…

  • CVE-2023-32214HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • CVE-2022-38476HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.

  • CVE-2022-36319HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

  • CVE-2022-26387HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7,…

  • CVE-2022-22741HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2022-22737HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

Page 46 of 105