Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2874-1 | thunderbird security update |
Debian DSA |
DSA-5034-1 | thunderbird security update |
EUVD |
EUVD-2021-24954 | Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2. |
Ubuntu USN |
USN-5248-1 | Thunderbird vulnerabilities |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T01:44:22.910Z
Reserved: 2021-08-10T00:00:00.000Z
Link: CVE-2021-38502
No data.
Status : Modified
Published: 2021-11-03T01:15:07.657
Modified: 2026-06-17T04:02:14.287
Link: CVE-2021-38502
OpenCVE Enrichment
No data.
-
CWE-319
Cleartext Transmission of Sensitive Information
- NVD-CWE-Other
Debian DLA
Debian DSA
EUVD
Ubuntu USN