cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 16 of 101
CVE-2026-16396P3HIGHCVSS 8.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16396 [HIGH] CWE-269 CVE-2026-16396: Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140. Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2010-3768P3CRITICALCVSS 9.3≤ 3.0.10v0.1+76 more2010-12-10
CVE-2010-3768 [CRITICAL] CWE-20 CVE-2010-3768: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3. Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (
nvd
CVE-2024-2607P3HIGHCVSS 8.1fixed in 115.9.0≥ unspecified, < 115.92024-03-19
CVE-2024-2607 [HIGH] CWE-123 CVE-2024-2607: Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *N Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
CVE-2024-5688P3HIGHCVSS 8.1fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5688 [HIGH] CWE-416 CVE-2024-5688: If a garbage collection was triggered at the right time, a use-after-free could have occurred during If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvdosv
CVE-2016-1935P3HIGHCVSS 8.8≥ 0, < 1:38.6.0+build1-0ubuntu0.14.04.12016-01-26
CVE-2016-1935 [HIGH] CVE-2016-1935: Buffer overflow in the BufferSubData function in Mozilla Firefox before 44 Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
osv
CVE-2025-9184P3HIGHCVSS 8.1fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9184 [HIGH] CWE-119 CVE-2025-9184: Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderb
nvdosv
CVE-2014-1524P3CRITICALCVSS 9.8fixed in 24.52014-04-30
CVE-2014-1524 [CRITICAL] CWE-120 CVE-2014-1524: The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code
nvdosv
CVE-2017-7828P3CRITICALCVSS 9.8fixed in 52.5.0≥ unspecified, < 52.52018-06-11
CVE-2017-7828 [CRITICAL] CWE-416 CVE-2017-7828: A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a potentially exploitable crash during these operations. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvdosv
CVE-2012-4185P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-4185 [CRITICAL] CWE-119 CVE-2012-4185: Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10. Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2018-5097P3CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5097 [CRITICAL] CWE-416 CVE-2018-5097: A use-after-free vulnerability can occur during XSL transformations when the source document for the A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2023-5174P3CRITICALCVSS 9.8fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5174 [CRITICAL] CWE-416 CVE-2023-5174: If Windows failed to duplicate a handle during process creation, the sandbox code may have inadverte If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vul
nvd
CVE-2024-6602P3CRITICALCVSS 9.8fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosv
CVE-2023-34416P3CRITICALCVSS 9.8fixed in 102.12≥ unspecified, < 102.122023-06-19
CVE-2023-34416 [CRITICAL] CWE-787 CVE-2023-34416: Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.
nvdosv
CVE-2024-9401P3CRITICALCVSS 9.8fixed in 128.3.0≥ 129.0, < 131.0+2 more2024-10-01
CVE-2024-9401 [CRITICAL] CWE-119 CVE-2024-9401: Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 12 Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thu
nvdosv
CVE-2024-8384P3CRITICALCVSS 9.8≥ unspecified, < 128.2≥ unspecified, < 115.152024-09-03
CVE-2024-8384 [CRITICAL] CWE-787 CVE-2024-8384: The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were de The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
nvdosv
CVE-2018-18356P3HIGHCVSS 8.8≥ 0, < 1:60.5.1-12018-12-11
CVE-2018-18356 [HIGH] CVE-2018-18356: An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71 An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
osv
CVE-2025-1017P3CRITICALCVSS 9.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1017 [CRITICAL] CWE-787 CVE-2025-1017: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thun
nvdosv
CVE-2025-8028P3CRITICALCVSS 9.8fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8028 [CRITICAL] CWE-1332 CVE-2025-8028: On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1
nvdosv
CVE-2025-11710P3CRITICALCVSS 9.8fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11710 [CRITICAL] CWE-200 CVE-2025-11710: A compromised web process using malicious IPC messages could have caused the privileged browser proc A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvdosv
CVE-2013-0768P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0768 [CRITICAL] CWE-787 CVE-2013-0768: Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via an HTML document that specifies invalid width and height values.
nvd
Mozilla Thunderbird vulnerabilities | cvebase