Vulnerabilities > Mozilla > Thunderbird > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-7825 Improper Input Validation vulnerability in multiple products
Several fonts on OS X display some Tibetan and Arabic characters as whitespace.
network
low complexity
debian mozilla CWE-20
5.3
2018-06-11 CVE-2017-7823 Cross-site Scripting vulnerability in multiple products
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified.
network
low complexity
redhat debian mozilla CWE-79
5.4
2018-06-11 CVE-2017-7791 Improper Input Validation vulnerability in multiple products
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content.
network
low complexity
debian redhat mozilla CWE-20
5.3
2018-06-11 CVE-2017-7782 Improper Privilege Management vulnerability in Mozilla Firefox
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections.
network
low complexity
mozilla CWE-269
5.3
2018-06-11 CVE-2017-7764 Improper Input Validation vulnerability in multiple products
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion.
network
low complexity
mozilla debian CWE-20
5.3
2018-06-11 CVE-2017-7763 Improper Input Validation vulnerability in multiple products
Default fonts on OS X display some Tibetan characters as whitespace.
network
low complexity
mozilla debian CWE-20
5.3
2018-06-11 CVE-2017-5466 Cross-site Scripting vulnerability in multiple products
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly.
network
low complexity
redhat mozilla CWE-79
6.1
2018-06-11 CVE-2017-5462 Incorrect Calculation vulnerability in multiple products
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over.
network
low complexity
debian mozilla CWE-682
5.3
2018-06-11 CVE-2017-5451 Improper Input Validation vulnerability in multiple products
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event.
network
low complexity
redhat mozilla CWE-20
4.3
2018-06-11 CVE-2017-5426 Incorrect Permission Assignment for Critical Resource vulnerability in Mozilla Firefox
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox.
network
low complexity
mozilla CWE-732
5.3