Vulnerabilities > Mozilla > Thunderbird > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-05 | CVE-2021-29970 | Use After Free vulnerability in Mozilla Firefox A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. | 8.8 |
2021-08-05 | CVE-2021-29976 | Out-of-bounds Write vulnerability in Mozilla Firefox Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. | 8.8 |
2021-06-24 | CVE-2021-23994 | Missing Initialization of Resource vulnerability in Mozilla Thunderbird A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. | 8.8 |
2021-06-24 | CVE-2021-23995 | Operation on a Resource after Expiration or Release vulnerability in Mozilla Thunderbird When Responsive Design Mode was enabled, it used references to objects that were previously freed. | 8.8 |
2021-06-24 | CVE-2021-23999 | Incorrect Comparison vulnerability in Mozilla Thunderbird If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. | 8.8 |
2021-06-24 | CVE-2021-24002 | Injection vulnerability in Mozilla Thunderbird When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. | 8.8 |
2021-06-24 | CVE-2021-29946 | Integer Overflow or Wraparound vulnerability in Mozilla Thunderbird Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. | 8.8 |
2021-06-24 | CVE-2021-29949 | Uncontrolled Search Path Element vulnerability in Mozilla Thunderbird When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. | 7.8 |
2021-06-24 | CVE-2021-29950 | Cleartext Storage of Sensitive Information vulnerability in Mozilla Thunderbird Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. | 7.5 |
2021-06-24 | CVE-2021-29964 | Out-of-bounds Read vulnerability in Mozilla Firefox A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. | 7.1 |