Mozilla

Thunderbird Esr

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Published 11.06.2018 21:29:15
  • Last modified 21.11.2024 04:08:15

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...

  • EPSS 0.88%
  • Published 11.06.2018 21:29:15
  • Last modified 21.11.2024 04:08:15

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and ...

  • EPSS 0.54%
  • Published 11.06.2018 21:29:15
  • Last modified 21.11.2024 04:08:16

In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartSc...

  • EPSS 4.12%
  • Published 11.06.2018 21:29:14
  • Last modified 21.11.2024 04:08:12

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This v...

  • EPSS 3.43%
  • Published 11.06.2018 21:29:03
  • Last modified 21.11.2024 03:27:31

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52,...

  • EPSS 0.73%
  • Published 17.02.2014 22:55:05
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message co...

Exploit
  • EPSS 37.27%
  • Published 17.02.2014 22:55:04
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message co...

  • EPSS 2.06%
  • Published 30.10.2013 10:55:04
  • Last modified 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allow remote atta...

  • EPSS 3.28%
  • Published 30.10.2013 10:55:04
  • Last modified 11.04.2025 00:51:21

Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to cause a denial of service (memory corruption and application c...

  • EPSS 0.48%
  • Published 30.10.2013 10:55:04
  • Last modified 11.04.2025 00:51:21

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote ...