Debian Thunderbird vulnerabilities
931 known vulnerabilities affecting debian/thunderbird.
Total CVEs
931
CISA KEV
10
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW90
Vulnerabilities
Page 10 of 47
CVE-2025-5283MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5283 [MEDIUM] CVE-2025-5283: chromium - Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remot...
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.55-1)
trixie: r
debian
CVE-2025-6430MEDIUMCVSS 6.1fixed in firefox 140.0-1 (sid)2025
CVE-2025-6430 [MEDIUM] CVE-2025-6430: firefox - When a file download is specified via the `Content-Disposition` header, that dir...
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
Scope: local
sid: resolved (fixed
debian
CVE-2025-8027MEDIUMCVSS 6.5fixed in firefox 141.0-1 (sid)2025
CVE-2025-8027 [MEDIUM] CVE-2025-8027: firefox - On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value ...
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Scope: local
sid: resolved (fixed in 141.0-1)
debian
CVE-2025-1935MEDIUMCVSS 4.3fixed in firefox 136.0-1 (sid)2025
CVE-2025-1935 [MEDIUM] CVE-2025-1935: firefox - A web page could trick a user into setting that site as the default handler for ...
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Scope: local
sid: resolved (fixed in 136.0-1)
debian
CVE-2025-10532MEDIUMCVSS 6.5fixed in firefox 143.0-1 (sid)2025
CVE-2025-10532 [MEDIUM] CVE-2025-10532: firefox - Incorrect boundary conditions in the JavaScript: GC component. This vulnerabilit...
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2025-10536MEDIUMCVSS 6.2fixed in firefox 143.0-1 (sid)2025
CVE-2025-10536 [MEDIUM] CVE-2025-10536: firefox - Information disclosure in the Networking: Cache component. This vulnerability af...
Information disclosure in the Networking: Cache component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2025-3523MEDIUMCVSS 6.4fixed in thunderbird 1:128.10.0esr-1~deb12u1 (bookworm)2025
CVE-2025-3523 [MEDIUM] CVE-2025-3523: thunderbird - When an email contains multiple attachments with external links via the X-Mozill...
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 a
debian
CVE-2025-11712MEDIUMCVSS 6.1fixed in firefox 144.0-1 (sid)2025
CVE-2025-11712 [MEDIUM] CVE-2025-11712: firefox - A malicious page could have used the type attribute of an OBJECT tag to override...
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and
debian
CVE-2025-1938MEDIUMCVSS 6.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1938 [MEDIUM] CVE-2025-1938: firefox - Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, a...
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
S
debian
CVE-2025-0240MEDIUMCVSS 4.0fixed in firefox 134.0-1 (sid)2025
CVE-2025-0240 [MEDIUM] CVE-2025-0240: firefox - Parsing a JavaScript module as JSON could, under some circumstances, cause cross...
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Scope: local
sid: resolved (fixed in 134.0-1)
debian
CVE-2025-5986MEDIUMCVSS 6.5fixed in thunderbird 1:128.12.0esr-1~deb12u1 (bookworm)2025
CVE-2025-5986 [MEDIUM] CVE-2025-5986: thunderbird - A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited ...
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed
debian
CVE-2025-13013MEDIUMCVSS 6.1fixed in firefox 145.0-1 (sid)2025
CVE-2025-13013 [MEDIUM] CVE-2025-13013: firefox - Mitigation bypass in the DOM: Core & HTML component. This vulnerability affects ...
Mitigation bypass in the DOM: Core & HTML component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2025-26695MEDIUMCVSS 5.3fixed in thunderbird 1:128.8.0esr-1~deb12u1 (bookworm)2025
CVE-2025-26695 [MEDIUM] CVE-2025-26695: thunderbird - When requesting an OpenPGP key from a WKD server, an incorrect padding size was ...
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.
Scope: local
bookworm: resolved (fixed in 1:128.8.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.8.0esr-1~deb11u1)
for
debian
CVE-2025-0242MEDIUMCVSS 6.5fixed in firefox 134.0-1 (sid)2025
CVE-2025-0242 [MEDIUM] CVE-2025-0242: firefox - Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, ...
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firef
debian
CVE-2025-4084LOWCVSS 5.72025
CVE-2025-4084 [MEDIUM] CVE-2025-4084: firefox-esr - Due to insufficient escaping of the special characters in the "copy as cURL" fea...
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23
debian
CVE-2025-11713LOWCVSS 8.12025
CVE-2025-11713 [HIGH] CVE-2025-11713: firefox - Insufficient escaping in the “Copy as cURL” feature could have been used to tric...
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Scope: local
sid: resolved
debian
CVE-2025-5265LOWCVSS 4.82025
CVE-2025-5265 [MEDIUM] CVE-2025-5265: firefox - Due to insufficient escaping of the ampersand character in the “Copy as cURL” fe...
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox
debian
CVE-2025-6426LOWCVSS 8.82025
CVE-2025-6426 [HIGH] CVE-2025-6426: firefox - The executable file warning did not warn users before opening files with the `te...
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
Scope: local
sid: resolved
debian
CVE-2025-4082LOWCVSS 5.92025
CVE-2025-4082 [MEDIUM] CVE-2025-4082: firefox - Modification of specific WebGL shader attributes could trigger an out-of-bounds ...
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138
debian
CVE-2025-1930LOWCVSS 8.82025
CVE-2025-1930 [HIGH] CVE-2025-1930: firefox - On Windows, a compromised content process could use bad StreamData sent over Aud...
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Scope: local
sid: resolved
debian