cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 12 of 101
CVE-2026-12328P3HIGHCVSS 8.1fixed in 152.0.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12328 [HIGH] CWE-120 CVE-2026-12328: Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefo Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Fir
nvdmozilla
CVE-2025-14333P3HIGHCVSS 8.1fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14333 [HIGH] CWE-787 CVE-2025-14333: Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunde
nvdosv
CVE-2012-4180P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-4180 [CRITICAL] CWE-119 CVE-2012-4180: Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firef Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2025-1009P3CRITICALCVSS 9.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1009 [CRITICAL] CWE-416 CVE-2025-1009: An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially explo An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2026-2796P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2796 [CRITICAL] CWE-843 CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2014-1544P3CRITICALCVSS 10.0≤ 24.6v24.0+7 more2014-07-23
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Networ Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a
nvd
CVE-2026-2771P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2771 [CRITICAL] CWE-125 CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, F Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2012-3963P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-3963 [CRITICAL] CWE-416 CVE-2012-3963: Use-after-free vulnerability in the js::gc::MapAllocToTraceKind function in Mozilla Firefox before 1 Use-after-free vulnerability in the js::gc::MapAllocToTraceKind function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2026-0892P3CRITICALCVSS 9.8fixed in 147.02026-01-13
CVE-2026-0892 [CRITICAL] CWE-119 CVE-2026-0892: Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2026-2785P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2785 [CRITICAL] CWE-824 CVE-2026-2785: Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fir Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2025-11721P3CRITICALCVSS 9.8≥ 143.0, < 144.02025-10-14
CVE-2025-11721 [CRITICAL] CWE-119 CVE-2025-11721: Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory cor Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
nvd
CVE-2026-4729P3CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4729 [CRITICAL] CWE-120 CVE-2026-4729: Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-2799P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2799 [CRITICAL] CWE-416 CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Th Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-12293P3CRITICALCVSS 9.8fixed in 152.0.02026-06-16
CVE-2026-12293 [CRITICAL] CWE-416 CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Th Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2011-0085P3CRITICALCVSS 10.0≤ 3.1.10v0.1+81 more2011-06-30
CVE-2011-0085 [CRITICAL] CWE-399 CVE-2011-0085: Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18 Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.
nvd
CVE-2011-2378P3CRITICALCVSS 10.0v3.0v3.0.1+20 more2011-08-18
CVE-2011-2378 [CRITICAL] CWE-94 CVE-2011-2378: The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
nvd
CVE-2026-12296P3CRITICALCVSS 9.6fixed in 140.12.0fixed in 152.0.02026-06-16
CVE-2026-12296 [CRITICAL] CWE-693 CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefo Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-12297P3CRITICALCVSS 9.6fixed in 140.12.0fixed in 152.0.02026-06-16
CVE-2026-12297 [CRITICAL] CWE-119 CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2013-5600P3CRITICALCVSS 10.0≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5600 [CRITICAL] CVE-2013-5600: Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code via vectors involving a blob: URL.
nvd
CVE-2013-5601P3CRITICALCVSS 10.0≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5601 [CRITICAL] CVE-2013-5601: Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Fire Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code via vectors related to a memory allocation through
nvd