VendorsMozillathunderbird3.1.10
Vulnerabilities

Mozilla Thunderbird 3.1.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2011-2999
Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.
Published 2011-09-29 · Modified
4.3EPSS 0.011
CVE-2010-5074
The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack.
Published 2011-12-07 · Modified
4.3EPSS 0.006
CVE-2011-2372
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
Published 2011-09-29 · Modified
3.5EPSS 0.009
← Prev2 / 2