Vulnerabilities > Mozilla > Thunderbird > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-02-26 CVE-2021-23969 As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects.
network
low complexity
mozilla debian
4.3
2021-02-26 CVE-2021-23968 Information Exposure Through an Error Message vulnerability in multiple products
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI.
network
low complexity
mozilla debian CWE-209
4.3
2021-01-07 CVE-2020-35111 Unspecified vulnerability in Mozilla Firefox ESR
When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs.
network
low complexity
mozilla
4.3
2021-01-07 CVE-2020-26978 Unspecified vulnerability in Mozilla Firefox ESR
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine.
network
low complexity
mozilla
6.1
2020-12-09 CVE-2020-26966 Unspecified vulnerability in Mozilla Firefox
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak.
network
low complexity
mozilla
6.5
2020-12-09 CVE-2020-26965 Improper Cross-boundary Removal of Sensitive Data vulnerability in Mozilla Firefox
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password.
network
low complexity
mozilla CWE-212
6.5
2020-12-09 CVE-2020-26961 Unspecified vulnerability in Mozilla Firefox
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.
network
low complexity
mozilla
6.5
2020-12-09 CVE-2020-26958 Cross-site Scripting vulnerability in Mozilla Firefox
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker.
network
low complexity
mozilla CWE-79
6.1
2020-12-09 CVE-2020-26956 Cross-site Scripting vulnerability in Mozilla Firefox
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS.
network
low complexity
mozilla CWE-79
6.1
2020-12-09 CVE-2020-26953 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user.
network
low complexity
mozilla CWE-1021
4.3