Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,775 CVEs tagged to mozilla / thunderbird607 Critical, 527 High, 615 Medium, 26 Low, 0 Unrated.

CVE-2024-8394

Published Sep 6, 2024

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6615

Published Jul 9, 2024

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6614

Published Jul 9, 2024

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 12…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6613

Published Jul 9, 2024

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 12…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6612

Published Jul 9, 2024

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6611

Published Jul 9, 2024

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6610

Published Jul 9, 2024

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerabil…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6609

Published Jul 9, 2024

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6608

Published Jul 9, 2024

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Fire…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6607

Published Jul 9, 2024

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `&lt;select&gt;` element over certain permission…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6606

Published Jul 9, 2024

Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6604

Published Jul 9, 2024

Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6603

Published Jul 9, 2024

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox <…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6602

Published Jul 9, 2024

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunder…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 376-400 of 1,775 CVEsPage 16 of 71