Thunderbird Esr
Vendor:
First CVE: Mar 14, 2012 · Active for 14 years
228
Total CVEs
More Total CVEs than 100% of tracked products
57.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Thunderbird Esr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2012
14 years ago
Most Recent CVE
Jun 11, 2018
2,968 days ago
CVE Severity & Scoring
Thunderbird Esr228 CVEs
29%
68%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (7.9%)
Unknown210 (92.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (7.0%)
High2 (0.9%)
Unknown210 (92.1%)
User Interaction
None12 (5.3%)
Unknown210 (92.1%)
Required6 (2.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (7.9%)
Unknown210 (92.1%)
Top CVEs
Signals from CVEs in this product scope (228 CVEs).
228 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1690HIGH Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c | Jun 26, 2013 | 8.8 | 96 | YES | YES |
CVE-2013-2566MEDIUM The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s | Mar 15, 2013 | 5.9 | 80 | NO | YES |
CVE-2013-0758HIGH Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaM | Jan 13, 2013 | 9.3 | 80 | NO | YES |
CVE-2013-0753HIGH Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before | Jan 13, 2013 | 9.3 | 77 | NO | YES |
CVE-2013-0757HIGH The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and Se | Jan 13, 2013 | 9.3 | 74 | NO | YES |
CVE-2012-3993HIGH The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaM | Oct 10, 2012 | 9.3 | 72 | NO | YES |
CVE-2013-1710HIGH The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey | Aug 7, 2013 | 10.0 | 66 | NO | YES |
CVE-2013-1675MEDIUM Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the ns | May 16, 2013 | 6.5 | 61 | YES | NO |
CVE-2018-5159CRITICAL An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead | Jun 11, 2018 | 9.8 | 54 | NO | YES |
CVE-2012-4186HIGH Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10 | Oct 10, 2012 | 9.3 | 38 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (228 CVEs).
CISA KEV
2 CVEs
0.9% of CVEs· 96th percentile
Metasploit
7 CVEs
3.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
3.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (228 CVEs).
Media Mentions
Signals from CVEs in this product scope (228 CVEs).
Top CNAs Publishing CVEs For Thunderbird Esr
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 17.0.9 | 13 | 8.9 | 5.1% | 0 | 1 |
| 17.0.8 | 19 | 8.2 | 4.8% | 0 | 1 |
| 17.0.7 | 28 | 7.7 | 5.1% | 0 | 2 |
| 17.0.6 | 37 | 7.8 | 4.8% | 0 | 2 |
| 17.0.5 | 46 | 8.1 | 5.1% | 0 | 3 |
| 17.0.4 | 52 | 8.0 | 4.7% | 0 | 3 |
| 17.0.3 | 53 | 8.0 | 4.8% | 0 | 3 |
| 17.0.2 | 53 | 8.0 | 4.8% | 0 | 3 |
| 17.0.10 | 2 | 4.3 | 4.9% | 0 | 1 |
| 17.0.1 | 53 | 8.0 | 4.8% | 0 | 3 |
| 17.0 | 53 | 8.0 | 4.8% | 0 | 3 |
| 10.0.7 | 1 | 9.3 | 42.6% | 0 | 1 |
| 10.0.6 | 10 | 9.1 | 7.8% | 0 | 1 |
| 10.0.5 | 24 | 8.2 | 5.3% | 0 | 1 |
| 10.0.4 | 37 | 8.2 | 5.0% | 0 | 1 |
| 10.0.3 | 44 | 7.8 | 4.6% | 0 | 1 |
| 10.0.2 | 56 | 7.6 | 4.3% | 0 | 1 |
| 10.0.1 | 56 | 7.6 | 4.3% | 0 | 1 |
| 10.0 | 56 | 7.6 | 4.3% | 0 | 1 |