CVEs (1,773)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-...Show more |
Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePho...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 16, 2026 Feb 2, 2006 N/Aยท v4 N/Aยท v3 6.4 MEDIUMยท v2 The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooper...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 16, 2026 Feb 2, 2006 N/Aยท v4 N/Aยท v3 5.1 MEDIUMยท v2 Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsx...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 16, 2026 Feb 2, 2006 N/Aยท v4 N/Aยท v3 5.1 MEDIUMยท v2 Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 16, 2026 Feb 2, 2006 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:s...Show more |
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending wi...Show more |
1Mozilla 3Firefox MozillaThunderbirdApr 16, 2026 Dec 31, 2005 N/Aยท v4 N/Aยท v3 5.0 MEDIUMยท v2 Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag. |
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authenticati...Show more |
Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks. |
run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files. |
1Mozilla 3Firefox MozillaThunderbirdApr 16, 2026 Jul 13, 2005 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such pr...Show more |
1Mozilla 3Firefox MozillaThunderbirdApr 16, 2026 May 2, 2005 N/Aยท v4 N/Aยท v3 5.0 MEDIUMยท v2 The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation...Show more |
1Mozilla 3Firefox MozillaThunderbirdApr 16, 2026 May 2, 2005 N/Aยท v4 N/Aยท v3 5.1 MEDIUMยท v2 Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitra...Show more |
1Mozilla 3Firefox MozillaThunderbirdApr 16, 2026 May 2, 2005 N/Aยท v4 N/Aยท v3 5.0 MEDIUMยท v2 String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string,...Show more |
Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version o...Show more |
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belo...Show more |
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy...Show more |
4Conectiva MozillaRedhat+1 more9Enterprise Linux Enterprise Linux DesktopFedora Core+6 moreApr 16, 2026 Jan 27, 2005 N/Aยท v4 N/Aยท v3 10.0 HIGHยท v2 Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code...Show more |
4Conectiva MozillaRedhat+1 more9Enterprise Linux Enterprise Linux DesktopFedora Core+6 moreApr 16, 2026 Jan 27, 2005 N/Aยท v4 N/Aยท v3 10.0 HIGHยท v2 Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbi...Show more |