Debian Thunderbird vulnerabilities
864 known vulnerabilities affecting debian/thunderbird.
Total CVEs
864
CISA KEV
10
actively exploited
Public exploits
23
Exploited in wild
16
Severity breakdown
CRITICAL166HIGH358MEDIUM317LOW23
Vulnerabilities
Page 8 of 44
CVE-2024-9401P3CRITICALCVSS 9.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9401 [CRITICAL] CVE-2024-9401: firefox - Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2...
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.
debian
CVE-2024-8384P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8384 [CRITICAL] CVE-2024-8384: firefox - The JavaScript garbage collector could mis-color cross-compartment objects if OO...
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Scope: local
sid: resolved (fixed in 130.0-1)
debian
CVE-2018-18356P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18356 [HIGH] CVE-2018-18356: chromium - An integer overflow in path handling lead to a use after free in Skia in Google ...
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in
debian
CVE-2025-1017P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1017 [CRITICAL] CVE-2025-1017: firefox - Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, a...
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
debian
CVE-2025-8028P3CRITICALCVSS 9.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8028 [CRITICAL] CVE-2025-8028: firefox - On arm64, a WASM `br_table` instruction with a lot of entries could lead to the ...
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Scop
debian
CVE-2025-11710P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11710 [CRITICAL] CVE-2025-11710: firefox - A compromised web process using malicious IPC messages could have caused the pri...
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Scope: local
sid: resolved (fixed in 144.0-1)
debian
CVE-2020-6831P3CRITICALCVSS 9.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6831 [CRITICAL] CVE-2020-6831: chromium - A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC....
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved
debian
CVE-2018-5127P3HIGHCVSS 8.8fixed in firefox 59.0-1 (sid)2018
CVE-2018-5127 [HIGH] CVE-2018-5127: firefox - A buffer overflow can occur when manipulating the SVG "animatedPathSegList" thro...
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Scope: local
sid: resolved (fixed in 59.0-1)
debian
CVE-2020-15969P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15969 [HIGH] CVE-2020-15969: chromium - Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fi
debian
CVE-2023-0767P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-0767 [HIGH] CVE-2023-0767: firefox - An attacker could construct a PKCS 12 cert bundle in such a way that could allow...
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2023-29541P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29541 [HIGH] CVE-2023-29541: firefox - Firefox did not properly handle downloads of files ending in <code>.desktop</cod...
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Andro
debian
CVE-2025-1011P3HIGHCVSS 8.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1011 [HIGH] CVE-2025-1011: firefox - A bug in WebAssembly code generation could have lead to a crash. It may have bee...
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Scope: local
sid: resolved (fixed in 135.0-1)
debian
CVE-2024-8382P3HIGHCVSS 8.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8382 [HIGH] CVE-2024-8382: firefox - Internal browser event interfaces were exposed to web content when privileged Ev...
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulner
debian
CVE-2026-2769P3HIGHCVSS 8.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2769 [HIGH] CVE-2026-2769: firefox - Use-after-free in the Storage: IndexedDB component. This vulnerability affects F...
Use-after-free in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-0882P3HIGHCVSS 8.8fixed in firefox 147.0-1 (sid)2026
CVE-2026-0882 [HIGH] CVE-2026-0882: firefox - Use-after-free in the IPC component. This vulnerability affects Firefox < 147, F...
Use-after-free in the IPC component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
debian
CVE-2025-14323P3HIGHCVSS 8.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14323 [HIGH] CVE-2025-14323: firefox - Privilege escalation in the DOM: Notifications component. This vulnerability aff...
Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2024-5696P3HIGHCVSS 8.6fixed in firefox 127.0-1 (sid)2024
CVE-2024-5696 [HIGH] CVE-2024-5696: firefox - By manipulating the text in an `<input>` tag, an attacker could have cause...
By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2025-13014P3HIGHCVSS 8.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13014 [HIGH] CVE-2025-13014: firefox - Use-after-free in the Audio/Video component. This vulnerability affects Firefox ...
Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2025-13020P3HIGHCVSS 8.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13020 [HIGH] CVE-2025-13020: firefox - Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects ...
Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2019-11693P3CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11693 [CRITICAL] CVE-2019-11693: firefox - The bufferdata function in WebGL is vulnerable to a buffer overflow with specifi...
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox
debian