Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 13 of 101
CVE-2012-5839P3CRITICALCVSS 9.3fixed in 17.02012-11-21
CVE-2012-5839 [CRITICAL] CWE-787 CVE-2012-5839: Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla
Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-0084P3CRITICALCVSS 10.0v3.0v3.0.1+22 more2011-08-18
CVE-2011-0084 [CRITICAL] CWE-94 CVE-2011-0084: The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangli
nvd
CVE-2009-0775P3CRITICALCVSS 10.0≤ 2.0.0.20v2.0.0.0+10 more2009-03-05
CVE-2009-0775 [CRITICAL] CWE-399 CVE-2009-0775: Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonke
Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
nvd
CVE-2026-8948P3CRITICALCVSS 9.1fixed in 151.0.02026-05-19
CVE-2026-8948 [CRITICAL] CWE-942 CVE-2026-8948: Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2025-6436P3HIGHCVSS 8.1fixed in 140.02025-06-24
CVE-2025-6436 [HIGH] CWE-119 CVE-2025-6436: Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvdosv
CVE-2013-1738P3CRITICALCVSS 9.3≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1738 [CRITICAL] CWE-399 CVE-2013-1738: Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.
Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code by leveraging incorrect garbage collection in situations involving default compartments and frame-chain restoration.
nvd
CVE-2026-16364P3CRITICALCVSS 9.1fixed in 153.02026-07-21
CVE-2026-16364 [CRITICAL] CWE-119 CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2024-3854P3HIGHCVSS 8.8fixed in 115.10≥ unspecified, < 115.102024-04-16
CVE-2024-3854 [HIGH] CWE-125 CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2025-10533P3HIGHCVSS 8.8fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10533 [HIGH] CWE-190 CVE-2025-10533: Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2013-0754P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0754 [CRITICAL] CWE-416 CVE-2013-0754: Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, F
Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors involving the trigger
nvd
CVE-2026-8974P3HIGHCVSS 8.8fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8974 [HIGH] CWE-119 CVE-2026-8974: Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2025-8035P3HIGHCVSS 8.8fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8035 [HIGH] CWE-119 CVE-2025-8035: Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Fir
nvdosv
CVE-2025-10537P3HIGHCVSS 8.8fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10537 [HIGH] CWE-119 CVE-2025-10537: Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunde
nvdosv
CVE-2026-16362P3HIGHCVSS 8.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16362 [HIGH] CWE-416 CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Fi
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16371P3HIGHCVSS 8.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16371 [HIGH] CWE-269 CVE-2026-16371: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153,
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16372P3HIGHCVSS 8.8fixed in 153.02026-07-21
CVE-2026-16372 [HIGH] CWE-269 CVE-2026-16372: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2022-46872P3HIGHCVSS 8.6fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46872 [HIGH] CWE-125 CVE-2022-46872: An attacker who compromised a content process could have partially escaped the sandbox to read arbit
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvdosv
CVE-2014-1557P3CRITICALCVSS 9.3≤ 24.6v24.0+7 more2014-07-23
CVE-2014-1557 [CRITICAL] CWE-94 CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a hig
nvdosv
CVE-2018-18492P3CRITICALCVSS 9.8fixed in 60.4.0≥ unspecified, < 60.42019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvdosv
CVE-2012-1941P3CRITICALCVSS 9.3v5.0v6.0+14 more2012-06-05
CVE-2012-1941 [CRITICAL] CWE-119 CVE-2012-1941: Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Fi
Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code by resizing a window displaying absolutely positioned
nvd