cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 10 of 101
CVE-2012-5829P3CRITICALCVSS 9.3fixed in 17.02012-11-21
CVE-2012-5829 [CRITICAL] CWE-787 CVE-2012-5829: Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, F Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-1486P3CRITICALCVSS 9.8fixed in 24.32014-02-06
CVE-2014-1486 [CRITICAL] CWE-416 CVE-2014-1486: Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
nvd
CVE-2023-5168P3CRITICALCVSS 9.8fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5168 [CRITICAL] CWE-787 CVE-2023-5168: A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbir
nvd
CVE-2018-18500P3CRITICALCVSS 9.8fixed in 60.52019-02-05
CVE-2018-18500 [CRITICAL] CWE-416 CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML e A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
nvdosv
CVE-2026-8956P3CRITICALCVSS 9.8fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8956 [CRITICAL] CWE-190 CVE-2026-8956: Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Fire Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2024-8385P3CRITICALCVSS 9.8≥ unspecified, < 128.22024-09-03
CVE-2024-8385 [CRITICAL] CWE-843 CVE-2024-8385: A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an expl A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvdosv
CVE-2026-0879P3CRITICALCVSS 9.8fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0879 [CRITICAL] CWE-119 CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability wa Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2025-11708P3CRITICALCVSS 9.8fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11708 [CRITICAL] CWE-416 CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, F Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvdosv
CVE-2026-2772P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2772 [CRITICAL] CWE-416 CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-16369P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16369 [CRITICAL] CWE-190 CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 1 Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-4720P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4720 [CRITICAL] CWE-120 CVE-2026-4720: Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun
nvdosv
CVE-2026-6748P3CRITICALCVSS 9.8fixed in 140.10.02026-04-21
CVE-2026-6748 [CRITICAL] CWE-457 CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2012-3968P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-3968 [CRITICAL] CWE-416 CVE-2012-3968: Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via vectors related to deletion of a fragment shader by its accessor.
nvd
CVE-2026-2767P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2767 [CRITICAL] CWE-416 CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2777P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2777 [CRITICAL] CWE-269 CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-16402P3CRITICALCVSS 9.8fixed in 153.02026-07-21
CVE-2026-16402 [CRITICAL] CWE-190 CVE-2026-16402: Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 an Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2025-11719P3CRITICALCVSS 9.8≥ 143.0, < 144.02025-10-14
CVE-2025-11719 [CRITICAL] CWE-416 CVE-2025-11719: Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
nvd
CVE-2026-5734P3CRITICALCVSS 9.8fixed in 140.9.1fixed in 149.0.22026-04-07
CVE-2026-5734 [CRITICAL] CWE-787 CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thun Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunde
nvd
CVE-2026-2792P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2792 [CRITICAL] CWE-787 CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thun
nvdosv
CVE-2026-8401P3CRITICALCVSS 9.8fixed in Thunderbird 140.11
CVE-2026-8401 [CRITICAL] Mozilla Foundation Security Advisory 2026-51: CVE-2026-8401 Mozilla Foundation Security Advisory 2026-51 CVE: CVE-2026-8401 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.11
mozilla
Mozilla Thunderbird vulnerabilities | cvebase