Mozilla

Thunderbird

2081 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 10.01.2025 19:15:31

Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulner...

  • EPSS 0.37%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 10.01.2025 19:15:31

OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbir...

  • EPSS 0.49%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 10.01.2025 19:15:31

If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An atta...

  • EPSS 0.82%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 05.05.2025 16:15:27

An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

  • EPSS 0.64%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 09.01.2025 17:15:08

Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10.

  • EPSS 0.64%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 18.12.2025 16:15:48

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects...

  • EPSS 0.6%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 18.12.2025 16:15:48

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thu...

  • EPSS 0.35%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 18.12.2025 16:15:48

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

  • EPSS 0.6%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 18.12.2025 16:15:48

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox ...

  • EPSS 0.64%
  • Veröffentlicht 02.06.2023 17:15:10
  • Zuletzt bearbeitet 18.12.2025 16:15:48

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firef...