Mozilla

Thunderbird

2081 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:15

The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature ...

  • EPSS 0.63%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:15

When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email hea...

  • EPSS 20.47%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:41

The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firef...

  • EPSS 0.67%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:41

When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerabili...

  • EPSS 1.53%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 07.05.2025 21:15:59

Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

  • EPSS 1.09%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:42

A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

  • EPSS 0.96%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:42

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

  • EPSS 1.41%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:42

The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

  • EPSS 0.95%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:42

A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6.

  • EPSS 1.04%
  • Veröffentlicht 19.12.2023 14:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:42

The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.