Vulnerabilities > Mozilla > Thunderbird > 0.7.2

DATE CVE VULNERABILITY TITLE RISK
2021-03-31 CVE-2021-23984 Authentication Bypass by Spoofing vulnerability in Mozilla Firefox
A malicious extension could have opened a popup window lacking an address bar.
network
mozilla CWE-290
4.3
2021-03-31 CVE-2021-23982 Inadequate Encryption Strength vulnerability in Mozilla Firefox
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections.
network
mozilla CWE-326
4.3
2021-03-31 CVE-2021-23981 Out-of-bounds Write vulnerability in Mozilla Firefox
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash.
network
mozilla CWE-787
5.8
2021-02-26 CVE-2021-23978 Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7.
network
mozilla debian
6.8
2021-02-26 CVE-2021-23964 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6.
network
mozilla CWE-787
6.8
2021-02-26 CVE-2021-23960 Unspecified vulnerability in Mozilla Firefox
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash.
network
mozilla
6.8
2021-02-26 CVE-2021-23954 Type Confusion vulnerability in Mozilla Firefox
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash.
network
mozilla CWE-843
6.8
2021-02-26 CVE-2021-23953 Unspecified vulnerability in Mozilla Firefox
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data.
network
mozilla
4.3
2021-02-26 CVE-2021-23973 Information Exposure Through an Error Message vulnerability in multiple products
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource.
4.3
2021-02-26 CVE-2021-23969 As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects.
network
mozilla debian
4.3