Mozilla Thunderbird vulnerabilities

1,818 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
58
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29

Vulnerabilities

Page 13 of 91
CVE-2025-1931HIGHCVSS 7.5fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1931 [HIGH] CWE-416 CVE-2025-1931: It was possible to cause a use-after-free in the content process side of a WebTransport connection, It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2025-1938MEDIUMCVSS 6.5fixed in 128.7.0≥ 129.0, < 135.02025-03-04
CVE-2025-1938 [MEDIUM] CWE-787 CVE-2025-1938: Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderb
nvdosv
CVE-2025-1935MEDIUMCVSS 4.3fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1935 [MEDIUM] CWE-79 CVE-2025-1935: A web page could trick a user into setting that site as the default handler for a custom URL protoco A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2025-1934MEDIUMCVSS 6.5fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1934 [MEDIUM] CVE-2025-1934: It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, poten It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2025-1017CRITICALCVSS 9.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1017 [CRITICAL] CWE-787 CVE-2025-1017: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thun
nvdosv
CVE-2025-1020CRITICALCVSS 9.8≥ 131.0, < 135.02025-02-04
CVE-2025-1020 [CRITICAL] CWE-787 CVE-2025-1020: Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2025-1016CRITICALCVSS 9.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1016 [CRITICAL] CWE-787 CVE-2025-1016: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, T Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefo
nvdosv
CVE-2025-1009CRITICALCVSS 9.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1009 [CRITICAL] CWE-416 CVE-2025-1009: An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially explo An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1014HIGHCVSS 8.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1014 [HIGH] CWE-295 CVE-2025-1014: Certificate length was not properly checked when added to a certificate store. In practice only trus Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1010HIGHCVSS 8.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1010 [HIGH] CWE-416 CVE-2025-1010: An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentiall An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1012HIGHCVSS 7.5fixed in 135.0≥ 128.0.1, < 128.7.02025-02-04
CVE-2025-1012 [HIGH] CWE-416 CVE-2025-1012: A race during concurrent delazification could have led to a use-after-free. This vulnerability was f A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1011HIGHCVSS 8.8fixed in 135.0≥ 128.0.1, < 128.7.02025-02-04
CVE-2025-1011 [HIGH] CWE-94 CVE-2025-1011: A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an at A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1013MEDIUMCVSS 6.5fixed in 128.7.0≥ 129.0, < 135.02025-02-04
CVE-2025-1013 [MEDIUM] CWE-362 CVE-2025-1013: A race condition could have led to private browsing tabs being opened in normal browsing windows. Th A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1015MEDIUMCVSS 5.4≥ 128.0.1, < 128.7.02025-02-04
CVE-2025-1015 [MEDIUM] CWE-79 CVE-2025-1015: The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attack The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page insi
nvdosv
CVE-2025-1018MEDIUMCVSS 5.3≥ 131.0, < 135.02025-02-04
CVE-2025-1018 [MEDIUM] CWE-1021 CVE-2025-1018: The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the use The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2025-0510MEDIUMCVSS 6.5≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-0510 [MEDIUM] CVE-2025-0510: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid gro Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
nvdosv
CVE-2025-1019MEDIUMCVSS 4.3≥ 131.0, < 135.02025-02-04
CVE-2025-1019 [MEDIUM] CWE-1021 CVE-2025-1019: The z-order of the browser windows could be manipulated to hide the fullscreen notification. This co The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2025-0247CRITICALCVSS 9.8fixed in 134.02025-01-07
CVE-2025-0247 [CRITICAL] CWE-787 CVE-2025-0247: Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.
nvdosv
CVE-2025-0241HIGHCVSS 7.7fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0241 [HIGH] CWE-401 CVE-2025-0241: When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially e When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2025-0239MEDIUMCVSS 4.0fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0239 [MEDIUM] CWE-295 CVE-2025-0239: When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirect When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv