Known vulnerabilities in Mozilla Thunderbird 128.1.1 - page 15

Vendor: Mozilla
Version: 128.1.1
Software CPE: cpe:2.3:a:mozilla:mozilla_thunderbird:*:*:*:*:*:*:*:*
Total vulnerabilities: 363
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Mozilla Thunderbird version 128.1.1 Mozilla Thunderbird 128.1.1 is affected by 363 vulnerabilities: 1 critical, 193 high, 108 medium, 61 low Critical High Medium Low

Vulnerabilities (363)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU108050 - Memory corruption
CVE-2025-4093
CWE-119 High
No
No
128.10 29.04.2025 SB2025042927
SB2025042929
SB2025043001
and 26 more
#VU108049 - Memory corruption
CVE-2025-4091
CWE-119 High
No
No
128.10, 138.0 29.04.2025 SB2025042927
SB2025042928
SB2025042929
and 27 more
#VU108048 - Out-of-bounds read
CVE-2025-4087
CWE-125 High
No
No
128.10, 138.0 29.04.2025 SB2025042927
SB2025042928
SB2025042929
and 27 more
#VU108047 - Improper input validation
CVE-2025-4084
CWE-20 Medium
No
No
128.10 29.04.2025 SB2025042927
SB2025042929
SB2025043001
and 8 more
#VU108046 - Protection Mechanism Failure
CVE-2025-4083
CWE-693 High
No
No
128.10, 138.0 29.04.2025 SB2025042927
SB2025042928
SB2025042929
and 27 more
#VU108045 - Memory corruption
CVE-2025-4082
CWE-119 High
No
No
128.10, 138.0 29.04.2025 SB2025042927
SB2025042928
SB2025042929
and 5 more
#VU107465 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-3523
CWE-451 Low
No
No
128.9.2, 137.0.2 15.04.2025 SB2025041536
SB2025041555
SB2025042487
and 13 more
#VU107464 - Exposure of sensitive information to an unauthorized actor
CVE-2025-2830
CWE-200 Low
No
No
128.9.2, 137.0.2 15.04.2025 SB2025041536
SB2025041555
SB2025042487
and 13 more
#VU107463 - Exposure of sensitive information to an unauthorized actor
CVE-2025-3522
CWE-200 Medium
No
No
128.9.2, 137.0.2 15.04.2025 SB2025041536
SB2025041555
SB2025042487
and 13 more
#VU106360 - Memory corruption
CVE-2025-3030
CWE-119 High
No
No
128.9.0, 137.0 01.04.2025 SB2025040129
SB2025040130
SB2025040131
and 40 more
#VU106359 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-3029
CWE-451 Medium
No
No
128.9.0, 137.0 01.04.2025 SB2025040129
SB2025040130
SB2025040131
and 40 more
#VU106358 - Use After Free
CVE-2025-3028
CWE-416 High
No
No
128.9.0, 137.0 01.04.2025 SB2025040129
SB2025040130
SB2025040131
and 40 more
#VU105318 - Improper input validation
CVE-2025-1936
CWE-20 Low
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105308 - Improper Restriction of Rendered UI Layers or Frames
CVE-2025-1935
CWE-1021 Low
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105307 - Resource Management Errors
CVE-2025-1934
CWE-399 Medium
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105306 - Out-of-bounds write
CVE-2025-1932
CWE-787 High
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105303 - Memory corruption
CVE-2025-1933
CWE-119 High
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105302 - Use After Free
CVE-2025-1931
CWE-416 High
No
No
128.8.0, 136.0 04.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105301 - Use After Free
CVE-2025-1930
CWE-416 High
No
No
128.8.0, 136.0 04.03.2025 SB2025030502
SB2025030503
SB2025030504
and 23 more
#VU101165 - Improper input validation
CVE-2024-43097
CWE-20 Low
No
No
128.8.0 03.12.2024 SB2024120367
SB2025030504
SB2025030505
and 16 more


Showing elements 281 - 300 out of 363