Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
56
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 10 of 91
CVE-2025-6427CRITICALCVSS 9.1≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6427 [CRITICAL] CVE-2025-6427: An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.
osv
CVE-2025-6424CRITICALCVSS 9.8≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6424 [CRITICAL] CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
osv
CVE-2025-6435HIGHCVSS 8.1fixed in 140.02025-06-24
CVE-2025-6435 [HIGH] CWE-434 CVE-2025-6435: If a user saved a response from the Network tab in Devtools using the Save As context menu option, t If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvdosv
CVE-2025-6432HIGHCVSS 8.6≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6432 [HIGH] CVE-2025-6432: When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140 and Thunderbird < 140.
osv
CVE-2025-6436HIGHCVSS 8.1fixed in 140.02025-06-24
CVE-2025-6436 [HIGH] CWE-119 CVE-2025-6436: Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvdosv
CVE-2025-6426HIGHCVSS 8.8≥ 0, < 1:128.12.0+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6426 [HIGH] CVE-2025-6426: The executable file warning did not warn users before opening files with the `terminal` extension The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
osv
CVE-2025-6434MEDIUMCVSS 4.3≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6434 [MEDIUM] CVE-2025-6434: The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140.
osv
CVE-2025-6430MEDIUMCVSS 6.1≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6430 [MEDIUM] CVE-2025-6430: When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and
osv
CVE-2025-6429MEDIUMCVSS 6.5≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6429 [MEDIUM] CVE-2025-6429: Firefox could have incorrectly parsed a URL and rewritten it to the youtube Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
osv
CVE-2025-6425MEDIUMCVSS 4.3≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6425 [MEDIUM] CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted bet An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunder
osv
CVE-2025-5986MEDIUMCVSS 6.5fixed in 128.11.1≥ 135.0, < 139.0.22025-06-11
CVE-2025-5986 [MEDIUM] CWE-451 CVE-2025-5986: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf fi A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email
nvdosv
CVE-2025-5269HIGHCVSS 8.1fixed in 128.11.02025-05-27
CVE-2025-5269 [HIGH] CWE-787 CVE-2025-5269: Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.11 and Thunderbird 128.11.
nvdosv
CVE-2025-5270HIGHCVSS 7.5≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-05-27
CVE-2025-5270 [HIGH] CVE-2025-5270: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.
osv
CVE-2025-5262HIGHCVSS 7.5fixed in 128.11.0fixed in 139.0+2 more2025-05-27
CVE-2025-5262 [HIGH] CWE-415 CVE-2025-5262: A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initi A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
cvelistv5nvd
CVE-2025-5268HIGHCVSS 8.1fixed in 128.11.0≥ 129.0, < 139.02025-05-27
CVE-2025-5268 [HIGH] CWE-119 CVE-2025-5268: Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128. Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunder
nvdosv
CVE-2025-5272HIGHCVSS 7.3fixed in 139.02025-05-27
CVE-2025-5272 [HIGH] CWE-787 CVE-2025-5272: Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
nvdosv
CVE-2025-5267MEDIUMCVSS 5.4≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5267 [MEDIUM] CVE-2025-5267: A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
osv
CVE-2025-5264MEDIUMCVSS 4.8≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5264 [MEDIUM] CVE-2025-5264: Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potential Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139,
osv
CVE-2025-5265MEDIUMCVSS 4.8≥ 0, < 1:128.12.0+build1-0ubuntu0.22.04.12025-05-27
CVE-2025-5265 [MEDIUM] CVE-2025-5265: Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potenti Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerabil
osv
CVE-2025-5263MEDIUMCVSS 4.3≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5263 [MEDIUM] CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
osv