Vulnerabilities > Mozilla > Thunderbird > 7.0.1

DATE CVE VULNERABILITY TITLE RISK
2011-12-21 CVE-2011-3661 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
network
low complexity
mozilla CWE-399
7.5
2011-12-21 CVE-2011-3660 Memory Corruption vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors.
network
low complexity
mozilla
critical
10.0
2011-11-09 CVE-2011-3654 Buffer Errors vulnerability in Mozilla Firefox and Thunderbird
The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
network
low complexity
mozilla CWE-119
critical
10.0
2011-11-09 CVE-2011-3653 Information Exposure vulnerability in Mozilla Firefox and Thunderbird
Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.
network
low complexity
mozilla apple CWE-200
5.0
2011-11-09 CVE-2011-3652 Buffer Errors vulnerability in Mozilla Firefox and Thunderbird
The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
network
low complexity
mozilla CWE-119
critical
10.0
2011-03-11 CVE-2011-1187 Information Exposure vulnerability in Google Chrome
Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
network
low complexity
google mozilla CWE-200
5.0