Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,775 CVEs tagged to mozilla / thunderbird607 Critical, 527 High, 615 Medium, 26 Low, 0 Unrated.

CVE-2025-0510

Published Feb 4, 2025

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixe…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-0247

Published Jan 7, 2025

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-0243

Published Jan 7, 2025

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that w…

CVSS 5.1 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-0242

Published Jan 7, 2025

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of…

CVSS 6.5 · Medium
evidence mentions
8
Buzz score
38.5
Vendor/product tagsBeta · best-effort

CVE-2025-0241

Published Jan 7, 2025

When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.…

CVSS 7.7 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-0240

Published Jan 7, 2025

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox…

CVSS 4.0 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-0239

Published Jan 7, 2025

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox E…

CVSS 4.0 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-0238

Published Jan 7, 2025

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-0237

Published Jan 7, 2025

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could h…

CVSS 5.4 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2024-11708

Published Nov 26, 2024

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11706

Published Nov 26, 2024

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatt…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11705

Published Nov 26, 2024

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This beh…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11704

Published Nov 26, 2024

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11702

Published Nov 26, 2024

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11701

Published Nov 26, 2024

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11700

Published Nov 26, 2024

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external application…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11699

Published Nov 26, 2024

Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11698

Published Nov 26, 2024

A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. Th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11697

Published Nov 26, 2024

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11696

Published Nov 26, 2024

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupporte…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11695

Published Nov 26, 2024

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affect…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11694

Published Nov 26, 2024

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility ext…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11693

Published Nov 26, 2024

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffect…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11692

Published Nov 26, 2024

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11691

Published Nov 26, 2024

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only af…

CVSS 8.8 · High
Showing 326-350 of 1,775 CVEsPage 14 of 71