Vulnerabilities > Mozilla > Thunderbird > 2.0.0.5

DATE CVE VULNERABILITY TITLE RISK
2008-02-29 CVE-2008-0304 Buffer Errors vulnerability in Mozilla Seamonkey and Thunderbird
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
network
low complexity
linux microsoft mozilla CWE-119
7.5
2008-02-12 CVE-2008-0420 Information Exposure vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read.
network
mozilla CWE-200
critical
9.3
2008-02-09 CVE-2008-0591 Unspecified vulnerability in Mozilla Firefox and Thunderbird
Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".
network
mozilla
4.3
2008-02-08 CVE-2008-0418 Path Traversal vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.
network
mozilla CWE-22
4.3
2007-09-12 CVE-2007-4841 Improper Input Validation vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845.
network
mozilla CWE-20
critical
9.3
2007-08-08 CVE-2007-3844 Unspecified vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
network
mozilla
4.3