Mozilla

Thunderbird

1542 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.56%
  • Published 05.08.2021 20:15:08
  • Last modified 21.11.2024 06:02:05

A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12...

  • EPSS 0.6%
  • Published 05.08.2021 20:15:08
  • Last modified 21.11.2024 06:02:05

Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbit...

Exploit
  • EPSS 0.13%
  • Published 24.06.2021 14:15:10
  • Last modified 21.11.2024 06:02:03

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection me...

Exploit
  • EPSS 0.31%
  • Published 24.06.2021 14:15:10
  • Last modified 21.11.2024 06:02:03

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird <...

  • EPSS 0.31%
  • Published 24.06.2021 14:15:10
  • Last modified 21.11.2024 06:02:04

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability af...

  • EPSS 0.48%
  • Published 24.06.2021 14:15:10
  • Last modified 21.11.2024 06:02:04

Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. ...

Exploit
  • EPSS 0.2%
  • Published 24.06.2021 14:15:09
  • Last modified 21.11.2024 05:52:09

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key wit...

  • EPSS 0.09%
  • Published 24.06.2021 14:15:09
  • Last modified 21.11.2024 05:52:10

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imp...

  • EPSS 0.05%
  • Published 24.06.2021 14:15:09
  • Last modified 21.11.2024 05:52:10

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, t...

  • EPSS 0.38%
  • Published 24.06.2021 14:15:09
  • Last modified 21.11.2024 05:52:10

A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.