Known vulnerabilities in Mozilla Thunderbird 128.1.1 - page 16

Vendor: Mozilla
Version: 128.1.1
Software CPE: cpe:2.3:a:mozilla:mozilla_thunderbird:*:*:*:*:*:*:*:*
Total vulnerabilities: 363
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Mozilla Thunderbird version 128.1.1 Mozilla Thunderbird 128.1.1 is affected by 363 vulnerabilities: 1 critical, 193 high, 108 medium, 61 low Critical High Medium Low

Vulnerabilities (363)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113123 - Cryptographic Issues
CVE-2025-26695
CWE-310 Low
No
No
136.0, 128.8.0 22.07.2025 SB2025030503
SB2025030504
SB2025072234
and 3 more
#VU113122 - Multiple Interpretations of UI Input
CVE-2025-26696
CWE-450 Low
No
No
136.0, 128.8.0 22.07.2025 SB2025030503
SB2025030504
SB2025072234
and 2 more
#VU105319 - Memory corruption
CVE-2025-1938
CWE-119 High
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 35 more
#VU105304 - Memory corruption
CVE-2025-1937
CWE-119 High
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 36 more
#VU103616 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-0510
CWE-451 Medium
No
No
128.7.0, 135.0 04.02.2025 SB2025020464
SB2025020465
SB2025020901
and 13 more
#VU103615 - Improper input validation
CVE-2025-1015
CWE-20 Low
Public exploit available
No
128.7.0 04.02.2025 SB2025020464
SB2025020603
SB2025020901
and 13 more
#VU103611 - Memory corruption
CVE-2025-1017
CWE-119 High
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103610 - Improper Certificate Validation
CVE-2025-1014
CWE-295 Low
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103609 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-1013
CWE-362 Low
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103608 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-1011
CWE-94 High
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103607 - Memory corruption
CVE-2025-1016
CWE-119 High
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103606 - Use After Free
CVE-2025-1012
CWE-416 High
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103605 - Use After Free
CVE-2025-1010
CWE-416 High
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU103604 - Use After Free
CVE-2025-1009
CWE-416 High
No
No
128.7.0, 135.0 04.02.2025 SB2025020463
SB2025020464
SB2025020465
and 34 more
#VU102427 - Memory corruption
CVE-2025-0241
CWE-119 High
No
No
128.6.0, 134.0 07.01.2025 SB2025010749
SB2025010801
SB2025010802
and 33 more
#VU102426 - Use After Free
CVE-2025-0240
CWE-416 Medium
No
No
128.6.0, 134.0 07.01.2025 SB2025010749
SB2025010801
SB2025010802
and 33 more
#VU102425 - Improper Certificate Validation
CVE-2025-0239
CWE-295 Medium
No
No
128.6.0, 134.0 07.01.2025 SB2025010749
SB2025010801
SB2025010802
and 33 more
#VU102424 - Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2025-0237
CWE-441 Low
No
No
128.6.0, 134.0 07.01.2025 SB2025010749
SB2025010801
SB2025010802
and 33 more
#VU102422 - Use After Free
CVE-2025-0238
CWE-416 High
No
No
128.6.0, 134.0 07.01.2025 SB2025010749
SB2025010801
SB2025010802
and 38 more
#VU100964 - Double Free
CVE-2024-11704
CWE-415 Medium
No
No
128.7.0, 133.0 26.11.2024 SB2024112669
SB2024112671
SB2024112870
and 15 more


Showing elements 301 - 320 out of 363