Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 11 of 101
CVE-2026-16410P3CRITICALCVSS 9.8fixed in 153.02026-07-21
CVE-2026-16410 [CRITICAL] CWE-843 CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-5735P3CRITICALCVSS 9.8fixed in 149.0.22026-04-07
CVE-2026-5735 [CRITICAL] CWE-787 CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evi
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
nvd
CVE-2026-2807P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2807 [CRITICAL] CWE-787 CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-8953P3CRITICALCVSS 9.6fixed in 140.112026-05-19
CVE-2026-8953 [CRITICAL] CWE-416 CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2011-2987P3CRITICALCVSS 10.0≤ 5.0v0.1+79 more2011-08-18
CVE-2011-2987 [CRITICAL] CWE-119 CVE-2011-2987: Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANGLE), as used in the WebGL impl
Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANGLE), as used in the WebGL implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products might allow remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-1522P3HIGHCVSS 8.8≤ 38.5.12016-02-13
CVE-2016-1522 [HIGH] CWE-119 CVE-2016-1522: Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
nvd
CVE-2026-16394P3UNKNOWNfixed in Thunderbird 153
CVE-2026-16394 Mozilla Foundation Security Advisory 2026-71: CVE-2026-16394
Mozilla Foundation Security Advisory 2026-71
CVE: CVE-2026-16394
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153
mozilla
CVE-2022-22744P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22744 [HIGH] CWE-116 CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped fo
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder
nvd
CVE-2017-5461P3CRITICALCVSS 9.8≥ unspecified, < 52.12017-05-11
CVE-2017-5461 [CRITICAL] CWE-787 CVE-2017-5461: Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x b
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
nvd
CVE-2012-1967P3CRITICALCVSS 10.0v5.0v6.0+15 more2012-07-18
CVE-2012-1967 [CRITICAL] CVE-2012-1967: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.
nvd
CVE-2024-2614P3HIGHCVSS 8.8fixed in 115.8.0≥ unspecified, < 115.92024-03-19
CVE-2024-2614 [HIGH] CWE-787 CVE-2024-2614: Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these b
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
CVE-2024-11697P3HIGHCVSS 8.8fixed in 128.5.0≥ 129.0, < 133.0+2 more2024-11-26
CVE-2024-11697 [HIGH] CWE-94 CVE-2024-11697: When handling keypress events, an attacker may have been able to trick a user into bypassing the "Op
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvdosv
CVE-2018-18498P3CRITICALCVSS 9.8fixed in 60.4≥ unspecified, < 60.42019-02-28
CVE-2018-18498 [CRITICAL] CWE-190 CVE-2018-18498: A potential vulnerability leading to an integer overflow can occur during buffer size calculations f
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvdosv
CVE-2025-8034P3HIGHCVSS 8.8fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8034 [HIGH] CWE-119 CVE-2025-8034: Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefo
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed
nvdosv
CVE-2025-11714P3HIGHCVSS 8.8fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11714 [HIGH] CWE-119 CVE-2025-11714: Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefo
nvdosv
CVE-2025-11715P3HIGHCVSS 8.8fixed in 140.4.0fixed in 144.02025-10-14
CVE-2025-11715 [HIGH] CWE-119 CVE-2025-11715: Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunde
nvdosv
CVE-2026-16366P3HIGHCVSS 8.8fixed in 153.02026-07-21
CVE-2026-16366 [HIGH] CWE-269 CVE-2026-16366: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16365P3HIGHCVSS 8.8fixed in 153.02026-07-21
CVE-2026-16365 [HIGH] CWE-269 CVE-2026-16365: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16401P3HIGHCVSS 8.8fixed in 153.02026-07-21
CVE-2026-16401 [HIGH] CWE-269 CVE-2026-16401: Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2018-5146P3HIGHCVSS 8.8fixed in 52.7.02018-06-11
CVE-2018-5146 [HIGH] CWE-787 CVE-2018-5146: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own co
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
nvdosv