Vulnerabilities > Mozilla > Thunderbird > High

DATE CVE VULNERABILITY TITLE RISK
2011-12-21 CVE-2011-3665 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling.
network
low complexity
mozilla CWE-399
7.5
2011-12-21 CVE-2011-3661 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
network
low complexity
mozilla CWE-399
7.5
2011-12-21 CVE-2011-3658 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
network
low complexity
mozilla CWE-399
7.5
2011-08-18 CVE-2011-2980 Remote Arbitrary Code Execution vulnerability in Mozilla Firefox and Thunderbird
Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
local
low complexity
mozilla
7.2
2011-06-30 CVE-2011-2373 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.
network
high complexity
mozilla CWE-399
7.6
2010-10-21 CVE-2010-3173 Cryptographic Issues vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
network
low complexity
mozilla CWE-310
7.5
2010-07-30 CVE-2010-2753 Use After Free vulnerability in multiple products
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
network
low complexity
mozilla suse opensuse CWE-416
8.8
2009-03-05 CVE-2009-0776 Information Exposure vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
network
mozilla CWE-200
7.1
2008-11-13 CVE-2008-5024 XML Injection (Aka Blind Xpath Injection) vulnerability in multiple products
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
network
low complexity
mozilla debian canonical CWE-91
7.5
2008-11-13 CVE-2008-5022 Improper Authentication vulnerability in multiple products
The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.
network
low complexity
mozilla debian canonical CWE-287
7.5