CVEs (1,729)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mozilla 2Firefox ThunderbirdNov 25, 2025 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: thi...Show more |
1Mozilla 2Firefox ThunderbirdNov 25, 2025 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vu...Show more |
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and...Show more |
2Mozilla Redhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreNov 25, 2025 Apr 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunde...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Apr 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has...Show more |
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the rem...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Apr 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60....Show more |
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is su...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Apr 26, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value i...Show more |
2Mozilla Redhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreNov 25, 2025 Apr 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which resu...Show more |
2Mozilla Redhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreNov 25, 2025 Apr 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is...Show more |
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. Thi...Show more |
2Mozilla Redhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreNov 25, 2025 Apr 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough...Show more |
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on resta...Show more |
A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a po...Show more |
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Feb 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin...Show more |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Feb 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vuln...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Feb 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin polic...Show more |