Vulnerabilities > Mozilla > Thunderbird > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-08-10 | CVE-2020-15648 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. | 6.5 |
2020-07-09 | CVE-2020-12421 | Improper Certificate Validation vulnerability in multiple products When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. | 6.5 |
2020-07-09 | CVE-2020-12418 | Out-of-bounds Read vulnerability in multiple products Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. | 6.5 |
2020-07-09 | CVE-2020-12405 | Use After Free vulnerability in multiple products When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. | 5.3 |
2020-07-09 | CVE-2020-12399 | Information Exposure Through Discrepancy vulnerability in multiple products NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. | 4.4 |
2020-05-26 | CVE-2020-12392 | Path Traversal vulnerability in multiple products The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. | 5.5 |
2020-05-22 | CVE-2020-12397 | Origin Validation Error vulnerability in multiple products By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. | 4.3 |
2020-03-25 | CVE-2020-6812 | Information Exposure vulnerability in multiple products The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. | 5.3 |
2020-03-02 | CVE-2020-6798 | Cross-site Scripting vulnerability in Mozilla Thunderbird If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. | 6.1 |
2020-03-02 | CVE-2020-6797 | Improper Input Validation vulnerability in Mozilla Firefox By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. | 4.3 |