Known vulnerabilities in thunderbird (Debian package) 68.4.1-1~deb9u1

Vendor: Debian
Version: 68.4.1-1~deb9u1
Software CPE: cpe:2.3:o:debian:thunderbird_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 26
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting thunderbird (Debian package) version 68.4.1-1~deb9u1 thunderbird (Debian package) 68.4.1-1~deb9u1 is affected by 26 vulnerabilities: 11 high, 12 medium, 3 low Critical High Medium Low

Vulnerabilities (26)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU60414 - Improper control of a resource through its lifetime
CVE-2022-22763
CWE-664 Medium
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 29 more
#VU60413 - Memory corruption
CVE-2022-22764
CWE-119 High
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 30 more
#VU60411 - Security Features
CVE-2022-22761
CWE-254 Medium
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 30 more
#VU60409 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22760
CWE-200 Medium
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 31 more
#VU60406 - Permissions, Privileges, and Access Controls
CVE-2022-22759
CWE-264 Medium
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 31 more
#VU60398 - Insufficient UI Warning of Dangerous Operations
CVE-2022-22756
CWE-357 Medium
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 30 more
#VU60395 - Permissions, Privileges, and Access Controls
CVE-2022-22754
CWE-264 High
No
No
1:91.6.0-1~deb10u1, 1:91.6.0-1~deb11u1 08.02.2022 SB2022020837
SB2022021015
SB2022021017
and 29 more
#VU49024 - Memory corruption
CVE-2020-35113
CWE-119 High
No
No
78.6.0-1~deb10u1 15.12.2020 SB2020121531
SB2020121533
SB2020121625
and 21 more
#VU49022 - Exposure of sensitive information to an unauthorized actor
CVE-2020-35111
CWE-200 Medium
No
No
78.6.0-1~deb10u1 15.12.2020 SB2020121531
SB2020121533
SB2020121625
and 20 more
#VU49020 - Permissions, Privileges, and Access Controls
CVE-2020-26978
CWE-264 Medium
No
No
78.6.0-1~deb10u1 15.12.2020 SB2020121531
SB2020121533
SB2020121625
and 20 more
#VU49016 - Type confusion
CVE-2020-26974
CWE-843 High
No
No
78.6.0-1~deb10u1 15.12.2020 SB2020121531
SB2020121533
SB2020121625
and 20 more
#VU49015 - Improper input validation
CVE-2020-26973
CWE-20 Medium
No
No
78.6.0-1~deb10u1 15.12.2020 SB2020121531
SB2020121533
SB2020121625
and 20 more
#VU49013 - Heap-based Buffer Overflow
CVE-2020-26971
CWE-122 High
No
No
78.6.0-1~deb10u1 15.12.2020 SB2020121531
SB2020121533
SB2020121625
and 22 more
#VU48790 - Use of Uninitialized Resource
CVE-2020-16042
CWE-908 Medium
No
No
78.6.0-1~deb10u1 02.12.2020 SB2020120501
SB2020120703
SB2020120912
and 29 more
#VU46018 - Use After Free
CVE-2020-15669
CWE-416 High
No
No
1:68.12.0-1~deb10u1 25.08.2020 SB2020082514
SB2020082520
SB2020082618
and 20 more
#VU46016 - Resource Management Errors
CVE-2020-15664
CWE-399 Medium
No
No
1:68.12.0-1~deb10u1 25.08.2020 SB2020082514
SB2020082520
SB2020082618
and 27 more
#VU29456 - Use After Free
CVE-2020-12420
CWE-416 High
No
No
1:68.10.0-1~deb9u1, 1:68.10.0-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29455 - Use After Free
CVE-2020-12419
CWE-416 High
No
No
1:68.10.0-1~deb9u1, 1:68.10.0-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29453 - Out-of-bounds read
CVE-2020-12418
CWE-125 Medium
No
No
1:68.10.0-1~deb9u1, 1:68.10.0-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29452 - Improper input validation
CVE-2020-12417
CWE-20 Medium
No
No
1:68.10.0-1~deb9u1, 1:68.10.0-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 22 more


Showing elements 1 - 20 out of 26