Vulnerabilities > Mozilla > Thunderbird > 2.0.0.12
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-24 | CVE-2021-23992 | Improper Verification of Cryptographic Signature vulnerability in Mozilla Thunderbird Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. | 4.3 |
2021-06-24 | CVE-2021-23993 | Improper Verification of Cryptographic Signature vulnerability in Mozilla Thunderbird An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. | 6.5 |
2021-06-24 | CVE-2021-23994 | Missing Initialization of Resource vulnerability in Mozilla Firefox A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. | 6.8 |
2021-06-24 | CVE-2021-23995 | Operation on a Resource after Expiration or Release vulnerability in Mozilla Firefox When Responsive Design Mode was enabled, it used references to objects that were previously freed. | 5.1 |
2021-06-24 | CVE-2021-23998 | Insufficient Verification of Data Authenticity vulnerability in Mozilla Firefox Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. | 4.3 |
2021-06-24 | CVE-2021-23999 | Incorrect Comparison vulnerability in Mozilla Thunderbird If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. | 6.8 |
2021-06-24 | CVE-2021-24002 | Injection vulnerability in Mozilla Thunderbird When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. | 8.8 |
2021-06-24 | CVE-2021-29946 | Integer Overflow or Wraparound vulnerability in Mozilla Firefox Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. | 6.8 |
2021-06-24 | CVE-2021-29948 | Race Condition vulnerability in Mozilla Thunderbird Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. | 1.9 |
2021-06-24 | CVE-2021-29949 | Uncontrolled Search Path Element vulnerability in Mozilla Thunderbird When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. | 4.4 |