Vulnerabilities > Mozilla > Thunderbird

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-36319 Unspecified vulnerability in Mozilla Thunderbird
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed.
network
low complexity
mozilla
7.5
2022-12-22 CVE-2022-38472 Origin Validation Error vulnerability in Mozilla Thunderbird
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar.
network
low complexity
mozilla CWE-346
6.5
2022-12-22 CVE-2022-38473 Improper Preservation of Permissions vulnerability in Mozilla Thunderbird
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access).
network
low complexity
mozilla CWE-281
8.8
2022-12-22 CVE-2022-38476 Use After Free vulnerability in Mozilla Thunderbird
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability.
network
high complexity
mozilla CWE-416
7.5
2022-12-22 CVE-2022-38477 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-38478 Out-of-bounds Write vulnerability in Mozilla Thunderbird
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-3032 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Mozilla Thunderbird
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked.
network
low complexity
mozilla CWE-610
6.5
2022-12-22 CVE-2022-3033 Cross-site Scripting vulnerability in Mozilla Thunderbird
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content.
network
low complexity
mozilla CWE-79
8.1
2022-12-22 CVE-2022-3034 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Thunderbird
When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent.
network
low complexity
mozilla CWE-1021
4.3
2022-12-22 CVE-2022-3155 Unspecified vulnerability in Mozilla Thunderbird
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file.
local
low complexity
mozilla
7.8