Vulnerabilities > Mozilla > Thunderbird > 68.1.1

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-6609 Unspecified vulnerability in Mozilla Firefox
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again.
network
low complexity
mozilla
8.8
2024-07-09 CVE-2024-6610 Unspecified vulnerability in Mozilla Firefox
Form validation popups could capture escape key presses.
network
low complexity
mozilla
4.3
2024-06-11 CVE-2024-5690 Information Exposure Through Discrepancy vulnerability in multiple products
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system.
network
low complexity
mozilla debian CWE-203
4.3
2024-06-11 CVE-2024-5691 Unspecified vulnerability in Mozilla Firefox
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window.
network
low complexity
mozilla
4.7
2024-05-14 CVE-2024-4367 A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
network
low complexity
mozilla debian open-xchange
8.8
2024-05-14 CVE-2024-4777 Out-of-bounds Write vulnerability in multiple products
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10.
network
low complexity
mozilla debian CWE-787
8.8
2024-04-16 CVE-2024-3863 Unspecified vulnerability in Mozilla Thunderbird
The executable file warning was not presented when downloading .xrm-ms files.
network
low complexity
mozilla
critical
9.8
2024-03-19 CVE-2024-2614 Out-of-bounds Write vulnerability in multiple products
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8.
network
low complexity
mozilla debian CWE-787
8.8
2024-03-19 CVE-2024-2616 Out-of-bounds Write vulnerability in Mozilla Firefox
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue.
network
low complexity
mozilla CWE-787
2.7
2024-02-20 CVE-2024-1547 Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown).
network
low complexity
mozilla debian
6.5