Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 3 of 44
CVE-2026-2760P3CRITICALCVSS 10.0fixed in firefox 148.0-1 (sid)2026
CVE-2026-2760 [CRITICAL] CVE-2026-2760: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c...
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-6424P3CRITICALCVSS 9.8fixed in firefox 140.0-1 (sid)2025
CVE-2025-6424 [CRITICAL] CVE-2025-6424: firefox - A use-after-free in FontFaceSet resulted in a potentially exploitable crash. Thi...
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
Scope: local
sid: resolved (fixed in 140.0-1)
debian
CVE-2026-2778P3CRITICALCVSS 10.0fixed in firefox 148.0-1 (sid)2026
CVE-2026-2778 [CRITICAL] CVE-2026-2778: firefox - Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp...
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2784P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2784 [CRITICAL] CVE-2026-2784: firefox - Mitigation bypass in the DOM: Security component. This vulnerability affects Fir...
Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-4919P3HIGHCVSS 8.8fixed in firefox 138.0.4-1 (sid)2025
CVE-2025-4919 [HIGH] CVE-2025-4919: firefox - An attacker was able to perform an out-of-bounds read or write on a JavaScript o...
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
Scope: local
sid: resolved (fixed in 138.0.4-1)
debian
CVE-2021-4140P3CRITICALCVSS 10.0fixed in firefox 96.0-1 (sid)2021
CVE-2021-4140 [CRITICAL] CVE-2021-4140: firefox - It was possible to construct specific XSLT markup that would be able to bypass a...
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian
CVE-2026-4689P3CRITICALCVSS 10.0fixed in firefox 149.0-1 (sid)2026
CVE-2026-4689 [CRITICAL] CVE-2026-4689: firefox - Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC...
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2020-6811P3HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6811 [HIGH] CVE-2020-6811: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Fire
debian
CVE-2025-14321P3CRITICALCVSS 9.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14321 [CRITICAL] CVE-2025-14321: firefox - Use-after-free in the WebRTC: Signaling component. This vulnerability affects Fi...
Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2026-4701P3CRITICALCVSS 9.8fixed in firefox 149.0-1 (sid)2026
CVE-2026-4701 [CRITICAL] CVE-2026-4701: firefox - Use-after-free in the JavaScript Engine component. This vulnerability affects Fi...
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4700P3CRITICALCVSS 9.8fixed in firefox 149.0-1 (sid)2026
CVE-2026-4700 [CRITICAL] CVE-2026-4700: firefox - Mitigation bypass in the Networking: HTTP component. This vulnerability affects ...
Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4717P3CRITICALCVSS 9.8fixed in firefox 149.0-1 (sid)2026
CVE-2026-4717 [CRITICAL] CVE-2026-4717: firefox - Privilege escalation in the Netmonitor component. This vulnerability affects Fir...
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-2780P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2780 [CRITICAL] CVE-2026-2780: firefox - Privilege escalation in the Netmonitor component. This vulnerability affects Fir...
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2789P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2789 [CRITICAL] CVE-2026-2789: firefox - Use-after-free in the Graphics: ImageLib component. This vulnerability affects F...
Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2786P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2786 [CRITICAL] CVE-2026-2786: firefox - Use-after-free in the JavaScript Engine component. This vulnerability affects Fi...
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2782P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2782 [CRITICAL] CVE-2026-2782: firefox - Privilege escalation in the Netmonitor component. This vulnerability affects Fir...
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2779P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2779 [CRITICAL] CVE-2026-2779: firefox - Incorrect boundary conditions in the Networking: JAR component. This vulnerabili...
Incorrect boundary conditions in the Networking: JAR component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2766P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2766 [CRITICAL] CVE-2026-2766: firefox - Use-after-free in the JavaScript Engine: JIT component. This vulnerability affec...
Use-after-free in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2765P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2765 [CRITICAL] CVE-2026-2765: firefox - Use-after-free in the JavaScript Engine component. This vulnerability affects Fi...
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-0884P3CRITICALCVSS 9.8fixed in firefox 147.0-1 (sid)2026
CVE-2026-0884 [CRITICAL] CVE-2026-0884: firefox - Use-after-free in the JavaScript Engine component. This vulnerability affects Fi...
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
debian