Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

1976 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisSin puntuar0.21%—Mozilla ThunderbirdAI30/9/202630/9/2026
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
AnalizadaCrítica (9.1)0.63%—Mozilla Thunderbird15/9/202624/9/2026
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
AnalizadaAlta (8.1)0.41%—Mozilla Thunderbird15/9/202624/9/2026
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
AnalizadaCrítica (9.8)0.54%—Mozilla Thunderbird15/9/202624/9/2026
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
AnalizadaAlta (7.5)0.42%—Mozilla Thunderbird1/9/20263/9/2026
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird…
AnalizadaAlta (7.5)0.27%—Mozilla Thunderbird1/9/20263/9/2026
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaAlta (7.5)0.26%—Mozilla Thunderbird1/9/20263/9/2026
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaCrítica (9.1)0.32%—Mozilla Thunderbird1/9/20263/9/2026
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.63%—Mozilla Thunderbird1/9/20263/9/2026
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed…
AnalizadaAlta (7.5)0.37%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155,…
AnalizadaAlta (7.5)0.43%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2,…
ModificadaCrítica (9.8)0.38%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155,…
ModificadaCrítica (9.8)0.56%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
ModificadaCrítica (9.8)0.63%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaCrítica (9.8)0.29%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaMedia (6.1)0.34%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaMedia (6.5)0.37%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
ModificadaMedia (4.3)0.21%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaMedia (6.1)0.38%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.57%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.29%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaAlta (7.5)0.44%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaAlta (8.8)0.34%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaAlta (7.5)0.44%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.29%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.