Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 15 of 101
CVE-2026-7321P3CRITICALCVSS 9.6fixed in 140.10.1fixed in 150.02026-04-28
CVE-2026-7321 [CRITICAL] CWE-120 CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulner
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
nvdmozilla
CVE-2013-0787P3CRITICALCVSS 9.3≤ 17.0.3v17.0+2 more2013-03-11
CVE-2013-0787 [CRITICAL] CWE-399 CVE-2013-0787: Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEdi
Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand
nvd
CVE-2021-24002P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-24002 [HIGH] CWE-74 CVE-2021-24002: When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvdosv
CVE-2026-4715P3CRITICALCVSS 9.1≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4715 [CRITICAL] CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4716P3CRITICALCVSS 9.1≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4716 [CRITICAL] CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2025-4083P3CRITICALCVSS 9.1fixed in 128.10.0fixed in 138.02025-04-29
CVE-2025-4083 [CRITICAL] CWE-653 CVE-2025-4083: A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs,
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and T
nvdosv
CVE-2026-4724P3CRITICALCVSS 9.1fixed in 149.02026-03-24
CVE-2026-4724 [CRITICAL] CWE-758 CVE-2026-4724: Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thu
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-16393P3CRITICALCVSS 9.1fixed in 153.02026-07-21
CVE-2026-16393 [CRITICAL] CWE-119 CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2022-22756P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22756 [HIGH] CWE-94 CVE-2022-22756: If a user was convinced to drag and drop an image to their desktop or other folder, the resulting ob
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdosv
CVE-2010-2766P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2766 [CRITICAL] CWE-94 CVE-2010-2766: The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
nvd
CVE-2026-2447P3HIGHCVSS 8.8fixed in 140.7.2≥ 141.0, < 147.0.22026-02-16
CVE-2026-2447 [HIGH] CWE-122 CVE-2026-2447: Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
nvdosv
CVE-2010-0176P3CRITICALCVSS 9.3≤ 3.0.3v0.1+59 more2010-04-05
CVE-2010-0176 [CRITICAL] CWE-399 CVE-2010-0176: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4;
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a
nvd
CVE-2017-5390P3CRITICALCVSS 9.8fixed in 45.7.0≥ unspecified, < 45.72018-06-11
CVE-2017-5390 [CRITICAL] CVE-2017-5390: The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for c
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2026-8975P3HIGHCVSS 8.8fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8975 [HIGH] CWE-119 CVE-2026-8975: Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunde
nvdmozilla
CVE-2026-12289P3HIGHCVSS 8.8fixed in 152.0.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12289 [HIGH] CWE-269 CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-8957P3HIGHCVSS 8.8fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8957 [HIGH] CWE-269 CVE-2026-8957: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2025-14328P3HIGHCVSS 8.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14328 [HIGH] CVE-2025-14328: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2025-14329P3HIGHCVSS 8.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14329 [HIGH] CVE-2025-14329: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2026-8973P3HIGHCVSS 8.8fixed in 151.0.02026-05-19
CVE-2026-8973 [HIGH] CWE-119 CVE-2026-8973: Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2025-8040P3HIGHCVSS 8.8fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8040 [HIGH] CWE-119 CVE-2025-8040: Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderb
nvdosv