Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 7 of 44
CVE-2025-9179P3CRITICALCVSS 9.8fixed in firefox 142.0-1 (sid)2025
CVE-2025-9179 [CRITICAL] CVE-2025-9179: firefox - An attacker was able to perform memory corruption in the GMP process which proce...
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and T
debian
CVE-2026-2762P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2762 [CRITICAL] CVE-2026-2762: firefox - Integer overflow in the JavaScript: Standard Library component. This vulnerabili...
Integer overflow in the JavaScript: Standard Library component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2774P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2774 [CRITICAL] CVE-2026-2774: firefox - Integer overflow in the Audio/Video component. This vulnerability affects Firefo...
Integer overflow in the Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-11709P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11709 [CRITICAL] CVE-2025-11709: firefox - A compromised web process was able to trigger out of bounds reads and writes in ...
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Scope: local
sid: resolved (fixed in 144.0-1)
debian
CVE-2020-6463P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6463 [HIGH] CVE-2020-6463: chromium - Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote...
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.
debian
CVE-2026-2781P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2781 [CRITICAL] CVE-2026-2781: firefox - Integer overflow in the Libraries component in NSS. This vulnerability affects F...
Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2021-24002P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-24002 [HIGH] CVE-2021-24002: firefox - When a user clicked on an FTP URL containing encoded newline characters (%0A and...
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2026-4715P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4715 [CRITICAL] CVE-2026-4715: firefox - Uninitialized memory in the Graphics: Canvas2D component. This vulnerability aff...
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4716P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4716 [CRITICAL] CVE-2026-4716: firefox - Incorrect boundary conditions, uninitialized memory in the JavaScript Engine com...
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2025-4083P3CRITICALCVSS 9.1fixed in firefox 138.0-1 (sid)2025
CVE-2025-4083 [CRITICAL] CVE-2025-4083: firefox - A process isolation vulnerability in Thunderbird stemmed from improper handling ...
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird <
debian
CVE-2022-22756P3HIGHCVSS 8.8fixed in firefox 97.0-1 (sid)2022
CVE-2022-22756 [HIGH] CVE-2022-22756: firefox - If a user was convinced to drag and drop an image to their desktop or other fold...
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
sid: resolved (fixed in 97.0-1)
debian
CVE-2026-2447P3LOWCVSS 8.8fixed in firefox 147.0.4-1 (sid)2026
CVE-2026-2447 [HIGH] CVE-2026-2447: firefox - Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Fi...
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
Scope: local
sid: resolved (fixed in 147.0.4-1)
debian
CVE-2025-14329P3HIGHCVSS 8.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14329 [HIGH] CVE-2025-14329: firefox - Privilege escalation in the Netmonitor component. This vulnerability affects Fir...
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2025-14328P3HIGHCVSS 8.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14328 [HIGH] CVE-2025-14328: firefox - Privilege escalation in the Netmonitor component. This vulnerability affects Fir...
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2024-2607P3HIGHCVSS 8.1fixed in firefox 124.0-1 (sid)2024
CVE-2024-2607 [HIGH] CVE-2024-2607: firefox - Return registers were overwritten which could have allowed an attacker to execut...
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2024-5688P3HIGHCVSS 8.1fixed in firefox 127.0-1 (sid)2024
CVE-2024-5688 [HIGH] CVE-2024-5688: firefox - If a garbage collection was triggered at the right time, a use-after-free could ...
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2017-7828P3CRITICALCVSS 9.8fixed in firefox 57.0-1 (sid)2017
CVE-2017-7828 [CRITICAL] CVE-2017-7828: firefox - A use-after-free vulnerability can occur when flushing and resizing layout becau...
A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a potentially exploitable crash during these operations. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
Scope: local
sid: resolved (fixed in 57.0-1)
debian
CVE-2018-5097P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5097 [CRITICAL] CVE-2018-5097: firefox - A use-after-free vulnerability can occur during XSL transformations when the sou...
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2024-6602P3CRITICALCVSS 9.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6602 [CRITICAL] CVE-2024-6602: firefox - A mismatch between allocator and deallocator could have led to memory corruption...
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2023-34416P3CRITICALCVSS 9.8fixed in firefox 114.0-1 (sid)2023
CVE-2023-34416 [CRITICAL] CVE-2023-34416: firefox - Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 1...
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.
Scope: local
sid: resolved (f
debian