Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,775 CVEs tagged to mozilla / thunderbird607 Critical, 527 High, 615 Medium, 26 Low, 0 Unrated.

CVE-2024-6601

Published Jul 9, 2024

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6600

Published Jul 9, 2024

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macO…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5702

Published Jun 11, 2024

Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5700

Published Jun 11, 2024

Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effo…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5693

Published Jun 11, 2024

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability af…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5688

Published Jun 11, 2024

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-4770

Published May 14, 2024

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3863

Published Apr 16, 2024

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3854

Published Apr 16, 2024

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3852

Published Apr 16, 2024

GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3302

Published Apr 16, 2024

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnera…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-2616

Published Mar 19, 2024

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 a…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 401-425 of 1,775 CVEsPage 17 of 71