mozilla thunderbird
500 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
username:password part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication crejavascript: URLs when used in object and embed tags. This vulnerability was fixed in Firefox 141, Firefbr_table instruction with a lot of entries could lead to the label being too far from the instruction causing tvpx_codec_enc_init_multi after a failed allocation when initializing the encoder for WebRTCPromise object. This vulnerability was fixed in F.url shortcut from the local filesystem, an unexpected file could be uploaded. *This bug opk12util, and specifically in the SEC_ASN1DecodeItem_Util functiNSC_DeriveKey inadvertently assumed that the phKey parameter is always non-NULL. When it was passed as NULL, a segmentation fasec_pkcs7_decoder_start_decrypt() when handling an error path. Under specific conditiloadManifestFromFile method during add-on signature verification.frame-src bypass and DOM-based XSS through the GContent-Disposition: attachment in the response header was not respected and did not foriframe. This vulnerabilitembed or object elements. This vulnerabilitwindow.open with specifically set protocol handlers, an attacker could determine if the appliresource://devtools originresource://pdf.js origin.StreamFilter which could be used to read and modify the<input> tag, an attacker could have caused corrupt memory leading to a potentially exploitaX-Frame-Options header, a sandboxed iframe could have presented a button that, if clicked by a usapplication/javascript respobrowser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was clSafeRefPtr, it could have triggered a crash or potentiallyAppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding() and AppendEncodedCharacters() could have experienced integerrequestPointerLock to cause the user's mouse toabout: dialog to show phishing content with an incorrect origin in the address bar. Thiunsafe-inline, the parent Content Security Policy could have overridden theShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virnsDNSService::Init. This issue appears to manifest rarely during start-up. This vulnerabnsWindow::PickerOpen(void) method was susceptible to a heap buffer overflow when running in headless mode. This vulnerabilitVideoBridge allowed any content process to use textures produced by remote decoders. This could be abused to escape the sannsTextFragment due to insufficient OOM handling. This vulnerability affectsreadlink may actually be smaller than necessary. *This buDrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver.PathRecording resulting in an out-of-bounds write, leadingFilterNodeD2D1 resulting in an out-of-bounds write, leadingHttpBaseChannel, if the load group was not available then it was ass.xll add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded witJS::CheckRegExpSyntax a Syntax Error could have been set which would end in calling convertToRuntimeErrorAndClearUpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to enteringRecordedSourceSurfaceCreation which resulted in a heap buffer overflow potentiallmStream could have been destroyed when initialized, which could have led to a use-after-fms-cxh and ms-cxh-full could have been leveraged to trigger a denial of service. *Note: This attack only affdatalist element to obscure the address bar. This vulnerability affects Firefox < 113, Firefconsole.log weren't acc