Vulnerabilities > Mozilla > Thunderbird > 45.7.0

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-5404 Use After Free vulnerability in multiple products
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it.
network
low complexity
debian redhat mozilla CWE-416
critical
9.8
2018-06-11 CVE-2017-5403 Use After Free vulnerability in Mozilla Thunderbird
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object.
network
low complexity
mozilla CWE-416
critical
9.8
2018-06-11 CVE-2017-5402 Use After Free vulnerability in multiple products
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts.
network
low complexity
debian redhat mozilla CWE-416
critical
9.8
2018-06-11 CVE-2017-5401 7PK - Errors vulnerability in multiple products
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error.
network
low complexity
debian redhat mozilla CWE-388
critical
9.8
2018-06-11 CVE-2017-5400 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.
network
low complexity
redhat debian mozilla CWE-119
critical
9.8
2018-06-11 CVE-2017-5399 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Memory safety bugs were reported in Firefox 51.
network
low complexity
mozilla CWE-119
critical
9.8
2018-06-11 CVE-2017-5398 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs were reported in Thunderbird 45.7.
network
low complexity
debian redhat mozilla CWE-119
critical
9.8
2018-06-11 CVE-2016-9899 Use After Free vulnerability in multiple products
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
network
low complexity
debian redhat mozilla CWE-416
critical
9.8
2017-03-15 CVE-2016-10196 Out-of-bounds Write vulnerability in multiple products
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
network
low complexity
debian libevent-project mozilla CWE-787
7.5