VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Mozilla
>
Thunderbird
> Medium
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2024-01-23
CVE-2024-0746
A Linux user opening the print preview dialog could have caused the browser to crash.
network
low complexity
mozilla
debian
6.5
6.5
2024-01-23
CVE-2024-0747
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy.
network
low complexity
mozilla
debian
6.5
6.5
2024-01-23
CVE-2024-0749
Origin Validation Error vulnerability in multiple products
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar.
network
low complexity
mozilla
debian
CWE-346
4.3
4.3
2024-01-23
CVE-2024-0753
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain.
network
low complexity
mozilla
debian
6.5
6.5
2023-12-19
CVE-2023-50761
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time.
network
low complexity
mozilla
debian
4.3
4.3
2023-12-19
CVE-2023-50762
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user.
network
low complexity
mozilla
debian
4.3
4.3
2023-12-19
CVE-2023-6857
Race Condition vulnerability in multiple products
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
network
high complexity
mozilla
debian
CWE-362
5.3
5.3
2023-12-19
CVE-2023-6860
The `VideoBridge` allowed any content process to use textures produced by remote decoders.
network
low complexity
mozilla
debian
6.5
6.5
2023-11-21
CVE-2023-6204
Out-of-bounds Read vulnerability in multiple products
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element.
network
low complexity
mozilla
debian
CWE-125
6.5
6.5
2023-11-21
CVE-2023-6205
Use After Free vulnerability in multiple products
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash.
network
low complexity
mozilla
debian
CWE-416
6.5
6.5
«
Previous
1
2
3
(current)
4
5
...
25
26
»
Next