Thunderbird Esr

Vendor:

First CVE: Mar 14, 2012 · Active for 14 years

228
Total CVEs
More Total CVEs than 100% of tracked products
57.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Thunderbird Esr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2012
14 years ago
Most Recent CVE
Jun 11, 2018
2,968 days ago

CVE Severity & Scoring

Thunderbird Esr228 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (7.9%)
Unknown210 (92.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (7.0%)
High2 (0.9%)
Unknown210 (92.1%)
User Interaction
None12 (5.3%)
Unknown210 (92.1%)
Required6 (2.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (7.9%)
Unknown210 (92.1%)

Top CVEs

Signals from CVEs in this product scope (228 CVEs).

228 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c
Jun 26, 20138.896YESYES
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s
Mar 15, 20135.980NOYES
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaM
Jan 13, 20139.380NOYES
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before
Jan 13, 20139.377NOYES
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and Se
Jan 13, 20139.374NOYES
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaM
Oct 10, 20129.372NOYES
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey
Aug 7, 201310.066NOYES
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the ns
May 16, 20136.561YESNO
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead
Jun 11, 20189.854NOYES
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10
Oct 10, 20129.338NONO

Exploit Exposure

Signals from CVEs in this product scope (228 CVEs).

CISA KEV
2 CVEs
0.9% of CVEs· 96th percentile
Metasploit
7 CVEs
3.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
3.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (228 CVEs).

Media Mentions

Signals from CVEs in this product scope (228 CVEs).

Top CNAs Publishing CVEs For Thunderbird Esr

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
17.0.9138.95.1%01
17.0.8198.24.8%01
17.0.7287.75.1%02
17.0.6377.84.8%02
17.0.5468.15.1%03
17.0.4528.04.7%03
17.0.3538.04.8%03
17.0.2538.04.8%03
17.0.1024.34.9%01
17.0.1538.04.8%03
17.0538.04.8%03
10.0.719.342.6%01
10.0.6109.17.8%01
10.0.5248.25.3%01
10.0.4378.25.0%01
10.0.3447.84.6%01
10.0.2567.64.3%01
10.0.1567.64.3%01
10.0567.64.3%01