Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 6 of 44
CVE-2024-11697P3HIGHCVSS 8.8fixed in firefox 133.0-1 (sid)2024
CVE-2024-11697 [HIGH] CVE-2024-11697: firefox - When handling keypress events, an attacker may have been able to trick a user in...
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Scope: local
sid: resolved (fixed in 133.0-1)
debian
CVE-2018-18498P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-18498 [CRITICAL] CVE-2018-18498: firefox - A potential vulnerability leading to an integer overflow can occur during buffer...
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
Scope: local
sid: resolved (fixed in 64.0-1)
debian
CVE-2025-8034P3HIGHCVSS 8.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8034 [HIGH] CVE-2025-8034: firefox - Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbir...
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, F
debian
CVE-2025-11714P3HIGHCVSS 8.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11714 [HIGH] CVE-2025-11714: firefox - Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird...
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4,
debian
CVE-2025-11715P3HIGHCVSS 8.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11715 [HIGH] CVE-2025-11715: firefox - Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox ...
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4
debian
CVE-2018-5146P3HIGHCVSS 8.8fixed in firefox 59.0.1-1 (sid)2018
CVE-2018-5146 [HIGH] CVE-2018-5146: firefox - An out of bounds memory write while processing Vorbis audio data was reported th...
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
Scope: local
sid: resolved (fixed in 59.0.1-1)
debian
CVE-2025-14333P3HIGHCVSS 8.1fixed in firefox 146.0-1 (sid)2025
CVE-2025-14333 [HIGH] CVE-2025-14333: firefox - Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox ...
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6
debian
CVE-2025-1009P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1009 [CRITICAL] CVE-2025-1009: firefox - An attacker could have caused a use-after-free via crafted XSLT data, leading to...
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Scope: local
sid: resolved (fixed in 135.0-1)
debian
CVE-2026-2771P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2771 [CRITICAL] CVE-2026-2771: firefox - Undefined behavior in the DOM: Core & HTML component. This vulnerability affects...
Undefined behavior in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2785P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2785 [CRITICAL] CVE-2026-2785: firefox - Invalid pointer in the JavaScript Engine component. This vulnerability affects F...
Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2024-3854P3HIGHCVSS 8.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3854 [HIGH] CVE-2024-3854: firefox - In some code patterns the JIT incorrectly optimized switch statements and genera...
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 125.0.1-1)
debian
CVE-2025-10533P3HIGHCVSS 8.8fixed in firefox 143.0-1 (sid)2025
CVE-2025-10533 [HIGH] CVE-2025-10533: firefox - Integer overflow in the SVG component. This vulnerability affects Firefox < 143,...
Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2025-8035P3HIGHCVSS 8.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8035 [HIGH] CVE-2025-8035: firefox - Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefo...
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13,
debian
CVE-2025-10537P3HIGHCVSS 8.8fixed in firefox 143.0-1 (sid)2025
CVE-2025-10537 [HIGH] CVE-2025-10537: firefox - Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox ...
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3
debian
CVE-2022-46872P3HIGHCVSS 8.6fixed in firefox 108.0-1 (sid)2022
CVE-2022-46872 [HIGH] CVE-2022-46872: firefox - An attacker who compromised a content process could have partially escaped the s...
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Scope: local
sid: resolved (fixed in 108.0-1)
debian
CVE-2018-18492P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-18492 [CRITICAL] CVE-2018-18492: firefox - A use-after-free vulnerability can occur after deleting a selection element due ...
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
Scope: local
sid: resolved (fixed in 64.0-1)
debian
CVE-2025-9185P3HIGHCVSS 8.1fixed in firefox 142.0-1 (sid)2025
CVE-2025-9185 [HIGH] CVE-2025-9185: firefox - Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbir...
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, F
debian
CVE-2026-0891P3HIGHCVSS 8.1fixed in firefox 147.0-1 (sid)2026
CVE-2026-0891 [HIGH] CVE-2026-0891: firefox - Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox ...
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
debian
CVE-2018-18335P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18335 [HIGH] CVE-2018-18335: chromium - Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a re...
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed
debian
CVE-2025-1016P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1016 [CRITICAL] CVE-2025-1016: firefox - Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, ...
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Fi
debian