Vulnerabilities > Mozilla > Thunderbird > 1.5.0.8

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2016-9895 7PK - Security Features vulnerability in multiple products
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript.
4.3
2018-06-11 CVE-2016-9893 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs were reported in Thunderbird 45.5.
network
low complexity
debian redhat mozilla CWE-119
7.5
2018-06-11 CVE-2016-9079 Use After Free vulnerability in multiple products
A use-after-free vulnerability in SVG Animation has been discovered.
network
low complexity
debian redhat mozilla microsoft torproject CWE-416
5.0
2018-06-11 CVE-2016-9074 Information Exposure vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
An existing mitigation of timing side-channel attacks is insufficient in some circumstances.
4.3
2018-06-11 CVE-2016-9066 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data.
network
low complexity
mozilla debian CWE-119
5.0
2018-06-11 CVE-2016-5297 Integer Overflow or Wraparound vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues.
network
low complexity
mozilla debian CWE-190
7.5
2018-06-11 CVE-2016-5296 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash.
network
low complexity
mozilla debian CWE-119
5.0
2018-06-11 CVE-2016-5294 Improper Input Validation vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process.
local
low complexity
mozilla microsoft CWE-20
2.1
2018-06-11 CVE-2016-5291 Improper Input Validation vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk.
local
low complexity
mozilla debian CWE-20
4.9
2018-06-11 CVE-2016-5290 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4.
network
low complexity
mozilla debian CWE-119
7.5