CVE-2018-5183
- EPSS 4.12%
- Published 11.06.2018 21:29:16
- Last modified 21.11.2024 04:08:17
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 5...
CVE-2018-5184
- EPSS 1.09%
- Published 11.06.2018 21:29:16
- Last modified 21.11.2024 04:08:17
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5185
- EPSS 0.35%
- Published 11.06.2018 21:29:16
- Last modified 21.11.2024 04:08:17
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5154
- EPSS 3.07%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:13
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Fir...
CVE-2018-5155
- EPSS 3.07%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:13
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox E...
CVE-2018-5157
- EPSS 0.62%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:13
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website....
CVE-2018-5158
- EPSS 58.98%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:14
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnera...
CVE-2018-5159
- EPSS 40.64%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:14
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This v...
CVE-2018-5161
- EPSS 0.93%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:14
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5162
- EPSS 0.97%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:14
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.