Mozilla

Thunderbird

2081 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.91%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:44:12

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access af...

  • EPSS 2.51%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:44:12

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote a...

  • EPSS 5.2%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:44:12

Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code v...

  • EPSS 3.46%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:44:13

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary...

  • EPSS 5.2%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:44:13

Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to exe...

  • EPSS 3.08%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:44:13

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to by...

  • EPSS 3.96%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 16.06.2026 23:44:10

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensit...

  • EPSS 0.3%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 16.06.2026 23:44:10

Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse e...

  • EPSS 1.87%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 16.06.2026 23:44:10

The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by provi...

  • EPSS 2.3%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 16.06.2026 23:44:11

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location objec...