Vulnerabilities > Mozilla > Thunderbird > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2017-7752 | Use After Free vulnerability in multiple products A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. | 8.8 |
2018-06-11 | CVE-2017-5467 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. | 7.5 |
2018-06-11 | CVE-2017-5454 | Information Exposure vulnerability in multiple products A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. | 7.5 |
2018-06-11 | CVE-2017-5449 | Improper Input Validation vulnerability in multiple products A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. | 7.5 |
2018-06-11 | CVE-2017-5445 | Improper Validation of Array Index vulnerability in multiple products A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. | 7.5 |
2018-06-11 | CVE-2017-5444 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. | 7.5 |
2018-06-11 | CVE-2017-5436 | Out-of-bounds Write vulnerability in multiple products An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. | 8.8 |
2018-06-11 | CVE-2017-5425 | Information Exposure vulnerability in Mozilla Firefox The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. | 7.5 |
2018-06-11 | CVE-2017-5422 | Improper Input Validation vulnerability in Mozilla Thunderbird If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. | 7.5 |
2018-06-11 | CVE-2017-5421 | Improper Input Validation vulnerability in Mozilla Thunderbird A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loaded. | 7.5 |