Vulnerabilities > Mozilla > Thunderbird > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-01 CVE-2024-9399 Unspecified vulnerability in Mozilla Thunderbird
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition.
network
low complexity
mozilla
7.5
2024-08-06 CVE-2024-7520 Type Confusion vulnerability in Mozilla Firefox
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution.
network
low complexity
mozilla CWE-843
8.8
2024-08-06 CVE-2024-7521 Improper Handling of Exceptional Conditions vulnerability in Mozilla Firefox
Incomplete WebAssembly exception handing could have led to a use-after-free.
network
low complexity
mozilla CWE-755
8.8
2024-08-06 CVE-2024-7522 Out-of-bounds Read vulnerability in Mozilla Firefox
Editor code failed to check an attribute value.
network
low complexity
mozilla CWE-125
8.8
2024-08-06 CVE-2024-7525 Incorrect Default Permissions vulnerability in Mozilla Firefox
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site.
network
low complexity
mozilla CWE-276
8.1
2024-08-06 CVE-2024-7527 Use After Free vulnerability in Mozilla Firefox
Unexpected marking work at the start of sweeping could have led to a use-after-free.
network
low complexity
mozilla CWE-416
8.8
2024-08-06 CVE-2024-7528 Use After Free vulnerability in Mozilla Firefox
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free.
network
low complexity
mozilla CWE-416
8.8
2024-07-09 CVE-2024-6609 Unspecified vulnerability in Mozilla Firefox
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again.
network
low complexity
mozilla
8.8
2024-05-14 CVE-2024-4367 A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
network
low complexity
mozilla debian open-xchange
8.8
2024-05-14 CVE-2024-4777 Out-of-bounds Write vulnerability in multiple products
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10.
network
low complexity
mozilla debian CWE-787
8.8