Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 21 of 44
CVE-2024-7525P3HIGHCVSS 8.1fixed in firefox 129.0-1 (sid)2024
CVE-2024-7525 [HIGH] CVE-2024-7525: firefox - It was possible for a web extension with minimal permissions to create a `Stream...
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2017-7793P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7793 [CRITICAL] CVE-2017-7793: firefox - A use-after-free vulnerability can occur in the Fetch API when the worker or the...
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Scope: local
sid: resolved (fixed in 56.0-1)
debian
CVE-2022-45414P3HIGHCVSS 8.1fixed in thunderbird 1:102.5.1-1 (bookworm)2022
CVE-2022-45414 [HIGH] CVE-2022-45414: thunderbird - If a Thunderbird user quoted from an HTML email, for example by replying to the ...
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown
debian
CVE-2025-3909P3HIGHCVSS 8.1fixed in thunderbird 1:128.10.1esr-1~deb12u1 (bookworm)2025
CVE-2025-3909 [HIGH] CVE-2025-3909: thunderbird - Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be ex...
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file dow
debian
CVE-2025-9180P3HIGHCVSS 8.1fixed in firefox 142.0-1 (sid)2025
CVE-2025-9180 [HIGH] CVE-2025-9180: firefox - Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerabilit...
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
Scope: local
sid: resolved (fixed in 142.0-1)
debian
CVE-2020-6814P3CRITICALCVSS 9.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6814 [CRITICAL] CVE-2020-6814: firefox - Mozilla developers reported memory safety bugs present in Firefox and Thunderbir...
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid
debian
CVE-2026-4699P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4699 [HIGH] CVE-2026-4699: firefox - Incorrect boundary conditions in the Layout: Text and Fonts component. This vuln...
Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4693P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4693 [HIGH] CVE-2026-4693: firefox - Incorrect boundary conditions in the Audio/Video: Playback component. This vulne...
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2024-1936P3HIGHCVSS 7.5fixed in thunderbird 1:115.9.0-1~deb12u1 (bookworm)2024
CVE-2024-1936 [HIGH] CVE-2024-1936: thunderbird - The encrypted subject of an email message could be incorrectly and permanently a...
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination,
debian
CVE-2024-3852P3HIGHCVSS 7.5fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3852 [HIGH] CVE-2024-3852: firefox - GetBoundName could return the wrong version of an object when JIT optimizations ...
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 125.0.1-1)
debian
CVE-2024-10459P3HIGHCVSS 7.5fixed in firefox 132.0-1 (sid)2024
CVE-2024-10459 [HIGH] CVE-2024-10459: firefox - An attacker could have caused a use-after-free when accessibility was enabled, l...
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Scope: local
sid: resolved (fixed in 132.0-1)
debian
CVE-2026-4709P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4709 [HIGH] CVE-2026-4709: firefox - Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerabil...
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4706P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4706 [HIGH] CVE-2026-4706: firefox - Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerab...
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2025-13016P3HIGHCVSS 7.5fixed in firefox 145.0-1 (sid)2025
CVE-2025-13016 [HIGH] CVE-2025-13016: firefox - Incorrect boundary conditions in the JavaScript: WebAssembly component. This vul...
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2006-0748P3HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-0748 [CRITICAL] CVE-2006-0748: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozil...
Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2026-2783P3HIGHCVSS 7.5fixed in firefox 148.0-1 (sid)2026
CVE-2026-2783 [HIGH] CVE-2026-2783: firefox - Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT c...
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2024-6603P3HIGHCVSS 7.4fixed in firefox 128.0-1 (sid)2024
CVE-2024-6603 [HIGH] CVE-2024-6603: firefox - In an out-of-memory scenario an allocation could fail but free would have been c...
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2025-13012P3HIGHCVSS 7.5fixed in firefox 145.0-1 (sid)2025
CVE-2025-13012 [HIGH] CVE-2025-13012: firefox - Race condition in the Graphics component. This vulnerability affects Firefox < 1...
Race condition in the Graphics component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2018-12361P3HIGHCVSS 8.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-12361 [HIGH] CVE-2018-12361: firefox - An integer overflow can occur in the SwizzleData code while calculating buffer s...
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
Scope: local
sid: resolved (fixed in 61.0-1)
debian
CVE-2019-17024P3HIGHCVSS 8.8fixed in firefox 72.0-1 (sid)2019
CVE-2019-17024 [HIGH] CVE-2019-17024: firefox - Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Scope: local
sid: resolved (fixed in 72.0-1)
debian