Description
Multiple serious vulnerabilities have been found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, bypass security restrictions and spoof user interface.
Below is a complete list of vulnerabilities:
- Multiple memory corruption vulnerabilities in Skia can be exploited remotely to cause denial of service;
- An information disclosure vulnerability in S/MIME can be exploited locally via chosen-ciphertext attack to obtain sensitive information;
- Multiple use-after-free vulnerabilities can be exploited remotely to cause denial of service;
- An integer overflow and out-of-bounds write vulnerabilities in Skia can be exploited remotely to cause denial of service;
- An unspecified vulnerability can be exploited remotely via specially crafted message headers to obtain sensitive information;
- An unspecified vulnerability can be exploited remotely via src attribute of remote images or links to obtain sensitive information;
- An unspecified vulnerability can be exploited remotely via attachment filename to spoof user interface;
- An unspecified vulnerability can be exploited remotely via specially crafted website to bypass security restrictions;
- A buffer overflow vulnerability can be exploited remotely to cause denial of service.
Original advisories
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2018-5154 critical
- CVE-2018-5155 critical
- CVE-2018-5159 critical
- CVE-2018-5168 warning
- CVE-2018-5174 warning
- CVE-2018-5150 critical
- CVE-2018-5183 critical
- CVE-2018-5184 warning
- CVE-2018-5161 warning
- CVE-2018-5162 warning
- CVE-2018-5170 warning
- CVE-2018-5178 high
- CVE-2018-5185 warning
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!