Vulnerabilities > Mozilla > Thunderbird
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-22 | CVE-2022-36319 | Unspecified vulnerability in Mozilla Thunderbird When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. | 7.5 |
2022-12-22 | CVE-2022-38472 | Origin Validation Error vulnerability in Mozilla Thunderbird An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. | 6.5 |
2022-12-22 | CVE-2022-38473 | Improper Preservation of Permissions vulnerability in Mozilla Thunderbird A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). | 8.8 |
2022-12-22 | CVE-2022-38476 | Use After Free vulnerability in Mozilla Thunderbird A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. | 7.5 |
2022-12-22 | CVE-2022-38477 | Out-of-bounds Write vulnerability in Mozilla Firefox Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. | 8.8 |
2022-12-22 | CVE-2022-38478 | Out-of-bounds Write vulnerability in Mozilla Thunderbird Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. | 8.8 |
2022-12-22 | CVE-2022-3032 | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Mozilla Thunderbird When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. | 6.5 |
2022-12-22 | CVE-2022-3033 | Cross-site Scripting vulnerability in Mozilla Thunderbird If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. | 8.1 |
2022-12-22 | CVE-2022-3034 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Thunderbird When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. | 4.3 |
2022-12-22 | CVE-2022-3155 | Unspecified vulnerability in Mozilla Thunderbird When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. | 7.8 |