Show filters
1,460 Total Results
Displaying 411-420 of 1,460
Sort by:
Attacker Value
Unknown
CVE-2021-29964
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
0
Attacker Value
Unknown
CVE-2021-29945
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
0
Attacker Value
Unknown
CVE-2021-29950
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
0
Attacker Value
Unknown
CVE-2021-29967
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
0
Attacker Value
Unknown
CVE-2021-29951
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.
0
Attacker Value
Unknown
CVE-2021-23991
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.
0
Attacker Value
Unknown
CVE-2021-23999
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
0
Attacker Value
Unknown
CVE-2021-29957
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.
0
Attacker Value
Unknown
CVE-2021-23992
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.
0
Attacker Value
Unknown
CVE-2021-23998
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
0