Known vulnerabilities in thunderbird (Debian package) 78.6.0-1~deb10u1

Vendor: Debian
Version: 78.6.0-1~deb10u1
Software CPE: cpe:2.3:o:debian:thunderbird_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 93
Public exploits: 5
Known exploited (KEV): 2
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting thunderbird (Debian package) version 78.6.0-1~deb10u1 thunderbird (Debian package) 78.6.0-1~deb10u1 is affected by 93 vulnerabilities: 2 critical, 40 high, 33 medium, 18 low Critical High Medium Low

Vulnerabilities (93)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65795 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-36318
CWE-79 Medium
No
No
1:91.12.0-1~deb10u1, 1:91.12.0-1~deb11u1 26.07.2022 SB2022072633
SB2022072634
SB2022072815
and 36 more
#VU65793 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-36319
CWE-451 Low
No
No
1:91.12.0-1~deb10u1, 1:91.12.0-1~deb11u1 26.07.2022 SB2022072633
SB2022072634
SB2022072815
and 36 more
#VU64769 - Improper Verification of Cryptographic Signature
CVE-2022-2226
CWE-347 Low
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 29.06.2022 SB2022062903
SB2022070102
SB2022070103
and 15 more
#VU64763 - Memory corruption
CVE-2022-34484
CWE-119 High
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU64762 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-2200
CWE-94 Medium
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 36 more
#VU64760 - Error Handling
CVE-2022-34472
CWE-388 Low
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 38 more
#VU64756 - Integer overflow
CVE-2022-34481
CWE-190 Medium
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 42 more
#VU64752 - Security Features
CVE-2022-34468
CWE-254 Medium
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 28.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU64751 - Use After Free
CVE-2022-34470
CWE-416 High
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 28.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU64750 - Improper Restriction of Rendered UI Layers or Frames
CVE-2022-34479
CWE-1021 Medium
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 28.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU63886 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-1834
CWE-451 Medium
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053126
SB2022060216
SB2022060503
and 14 more
#VU63881 - Security Features
CVE-2022-31744
CWE-254 Medium
No
No
1:91.11.0-1~deb10u1, 1:91.11.0-1~deb11u1 31.05.2022 SB2022053116
SB2022061323
SB2022062901
and 32 more
#VU63879 - Memory corruption
CVE-2022-31747
CWE-119 High
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63878 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31742
CWE-200 Medium
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63877 - Use of Uninitialized Variable
CVE-2022-31741
CWE-457 High
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 40 more
#VU63876 - Memory corruption
CVE-2022-31740
CWE-119 High
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63874 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-31738
CWE-451 Medium
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63873 - Out-of-bounds write
CVE-2022-31737
CWE-787 High
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63872 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31736
CWE-200 Low
No
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63501 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-1802
CWE-94 High
Public exploit available
No
1:91.10.0-1~deb10u1, 1:91.10.0-1~deb11u1 21.05.2022 SB2022052102
SB2022052103
SB2022052104
and 32 more


Showing elements 1 - 20 out of 93