Search CVE reports


Toggle filters

721 – 730 of 2337 results


CVE-2023-23597

Medium priority

Some fixes available 2 of 11

A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited...

7 affected packages

firefox, mozjs78, mozjs91, thunderbird, mozjs38...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Fixed Fixed
mozjs78 Not in release Ignored Not in release Not in release
mozjs91 Ignored Not in release Not in release
thunderbird Not affected Not affected Not in release Ignored
mozjs38 Not in release Not in release Ignored
mozjs52 Not in release Ignored Ignored
mozjs68 Not in release Ignored Not in release
Show all 7 packages Show less packages

CVE-2022-46882

Medium priority
Fixed

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

1 affected package

thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-46881

Medium priority
Fixed

An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the...

1 affected package

thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-46880

Medium priority
Fixed

A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was...

1 affected package

thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-46875

Medium priority
Not affected

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not in release Ignored
thunderbird Not affected Not in release Ignored
Show less packages

CVE-2022-45414

Medium priority
Fixed

If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to...

1 affected package

thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Fixed Fixed Fixed
Show less packages

CVE-2022-36314

Medium priority

Some fixes available 2 of 3

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other...

2 affected packages

thunderbird, firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Fixed Fixed Ignored
firefox Not affected Not in release Not affected
Show less packages

CVE-2022-34478

Medium priority
Not affected

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities,...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not in release Not affected
thunderbird Not affected Not in release Not affected
Show less packages

CVE-2022-31739

Medium priority
Ignored

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only...

8 affected packages

mozjs38, mozjs52, mozjs68, mozjs78, mozjs91...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Ignored Not in release
mozjs78 Not in release Ignored Not in release Not in release
mozjs91 Not in release Ignored Not in release Not in release
firefox-esr
firefox Not affected Not affected Not in release Not affected
thunderbird Not affected Not affected Not in release Not affected
Show all 8 packages Show less packages

CVE-2022-3155

Medium priority
Not affected

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was...

1 affected package

thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Not affected Not in release Not affected
Show less packages