โ† Back

Thunderbird

thunderbird

Vendor: Mozilla โ€ข 1,773 CVEs

CVEs (1,773)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Thunderbird
Apr 16, 2026
Feb 24, 2006
N/Aยท v4
N/Aยท v3
9.3 HIGHยท v2
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-...Show more
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.Show less
1Mozilla
1Thunderbird
Apr 16, 2026
Feb 22, 2006
N/Aยท v4
N/Aยท v3
2.6 LOWยท v2
Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePho...Show more
Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePhone field.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 16, 2026
Feb 2, 2006
N/Aยท v4
N/Aยท v3
6.4 MEDIUMยท v2
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooper...Show more
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 16, 2026
Feb 2, 2006
N/Aยท v4
N/Aยท v3
5.1 MEDIUMยท v2
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsx...Show more
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 16, 2026
Feb 2, 2006
N/Aยท v4
N/Aยท v3
5.1 MEDIUMยท v2
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator...Show more
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 16, 2026
Feb 2, 2006
N/Aยท v4
N/Aยท v3
7.5 HIGHยท v2
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:s...Show more
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.Show less
1Mozilla
1Thunderbird
Apr 16, 2026
Jan 18, 2006
N/Aยท v4
N/Aยท v3
5.1 MEDIUMยท v2
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending wi...Show more
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.Show less
1Mozilla
3Firefox
MozillaThunderbird
Apr 16, 2026
Dec 31, 2005
N/Aยท v4
N/Aยท v3
5.0 MEDIUMยท v2
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.
1Mozilla
1Thunderbird
Apr 16, 2026
Nov 1, 2005
N/Aยท v4
N/Aยท v3
2.6 LOWยท v2
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authenticati...Show more
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.Show less
1Mozilla
2Firefox
Thunderbird
Apr 16, 2026
Aug 17, 2005
N/Aยท v4
N/Aยท v3
2.6 LOWยท v2
Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.
1Mozilla
1Thunderbird
Apr 16, 2026
Aug 5, 2005
N/Aยท v4
N/Aยท v3
2.1 LOWยท v2
run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
1Mozilla
3Firefox
MozillaThunderbird
Apr 16, 2026
Jul 13, 2005
N/Aยท v4
N/Aยท v3
7.5 HIGHยท v2
Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such pr...Show more
Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.Show less
1Mozilla
3Firefox
MozillaThunderbird
Apr 16, 2026
May 2, 2005
N/Aยท v4
N/Aยท v3
5.0 MEDIUMยท v2
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation...Show more
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.Show less
1Mozilla
3Firefox
MozillaThunderbird
Apr 16, 2026
May 2, 2005
N/Aยท v4
N/Aยท v3
5.1 MEDIUMยท v2
Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitra...Show more
Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.Show less
1Mozilla
3Firefox
MozillaThunderbird
Apr 16, 2026
May 2, 2005
N/Aยท v4
N/Aยท v3
5.0 MEDIUMยท v2
String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string,...Show more
String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.Show less
1Mozilla
1Thunderbird
Apr 16, 2026
May 2, 2005
N/Aยท v4
N/Aยท v3
5.0 MEDIUMยท v2
Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version o...Show more
Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.Show less
1Mozilla
3Firefox
MozillaThunderbird
Apr 16, 2026
May 2, 2005
N/Aยท v4
N/Aยท v3
2.1 LOWยท v2
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belo...Show more
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.Show less
1Mozilla
2Mozilla
Thunderbird
Apr 16, 2026
Feb 15, 2005
N/Aยท v4
N/Aยท v3
5.0 MEDIUMยท v2
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy...Show more
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.Show less
4Conectiva
MozillaRedhat+1 more
9Enterprise Linux
Enterprise Linux DesktopFedora Core+6 more
Apr 16, 2026
Jan 27, 2005
N/Aยท v4
N/Aยท v3
10.0 HIGHยท v2
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code...Show more
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.Show less
4Conectiva
MozillaRedhat+1 more
9Enterprise Linux
Enterprise Linux DesktopFedora Core+6 more
Apr 16, 2026
Jan 27, 2005
N/Aยท v4
N/Aยท v3
10.0 HIGHยท v2
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbi...Show more
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.Show less