Vulnerabilities > Mozilla > Thunderbird
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-22 | CVE-2022-45414 | Unspecified vulnerability in Mozilla Thunderbird If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. | 8.1 |
2022-12-22 | CVE-2022-45416 | Information Exposure Through Discrepancy vulnerability in Mozilla Firefox Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. | 6.5 |
2022-12-22 | CVE-2022-45418 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. | 6.1 |
2022-12-22 | CVE-2022-45420 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. | 6.5 |
2022-12-22 | CVE-2022-45421 | Out-of-bounds Write vulnerability in Mozilla Firefox Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. | 8.8 |
2022-12-22 | CVE-2022-46872 | Unspecified vulnerability in Mozilla Firefox An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. | 8.6 |
2022-12-22 | CVE-2022-46874 | Unspecified vulnerability in Mozilla Firefox A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. | 8.8 |
2022-12-22 | CVE-2022-46875 | Unspecified vulnerability in Mozilla Firefox The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. | 6.5 |
2022-12-22 | CVE-2022-46878 | Out-of-bounds Write vulnerability in Mozilla Firefox Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. | 8.8 |
2022-12-22 | CVE-2022-46880 | Use After Free vulnerability in Mozilla Firefox A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. | 6.5 |