Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 17 of 101
CVE-2014-1514P3CRITICALCVSS 9.8fixed in 24.42014-03-19
CVE-2014-1514 [CRITICAL] CWE-787 CVE-2014-1514: vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird bef
vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by trig
nvd
CVE-2008-0418P4MEDIUMCVSS 4.3PoC≤ 2.0.0.112008-02-08
CVE-2008-0418 [MEDIUM] CWE-22 CVE-2008-0418: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, a
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.
nvd
CVE-2026-16408P3UNKNOWNfixed in Thunderbird 153
CVE-2026-16408 Mozilla Foundation Security Advisory 2026-71: CVE-2026-16408
Mozilla Foundation Security Advisory 2026-71
CVE: CVE-2026-16408
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153
mozilla
CVE-2026-16395P3UNKNOWNfixed in Thunderbird 153
CVE-2026-16395 Mozilla Foundation Security Advisory 2026-71: CVE-2026-16395
Mozilla Foundation Security Advisory 2026-71
CVE: CVE-2026-16395
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153
mozilla
CVE-2026-16411P3UNKNOWNfixed in Thunderbird 153
CVE-2026-16411 Mozilla Foundation Security Advisory 2026-71: CVE-2026-16411
Mozilla Foundation Security Advisory 2026-71
CVE: CVE-2026-16411
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153
mozilla
CVE-2020-6831P3CRITICALCVSS 9.8fixed in 68.8.0≥ unspecified, < 68.8.02020-05-26
CVE-2020-6831 [CRITICAL] CWE-787 CVE-2020-6831: A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvdosv
CVE-2026-16406P3UNKNOWNfixed in Thunderbird 153
CVE-2026-16406 Mozilla Foundation Security Advisory 2026-71: CVE-2026-16406
Mozilla Foundation Security Advisory 2026-71
CVE: CVE-2026-16406
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153
mozilla
CVE-2018-5127P3HIGHCVSS 8.8fixed in 52.7.0≥ unspecified, < 52.72018-06-11
CVE-2018-5127 [HIGH] CWE-119 CVE-2018-5127: A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This res
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvdosv
CVE-2017-7778P3CRITICALCVSS 9.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7778 [CRITICAL] CWE-119 CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2020-15969P3HIGHCVSS 8.8≥ 0, < 1:78.4.0-12020-11-03
CVE-2020-15969 [HIGH] CVE-2020-15969: Use after free in WebRTC in Google Chrome prior to 86
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
osv
CVE-2013-0750P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0750 [CRITICAL] CWE-190 CVE-2013-0750: Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x b
Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted string concatenation, leading to imp
nvd
CVE-2013-6674P4MEDIUMCVSS 4.3PoCv17.0v17.0.1+7 more2014-02-17
CVE-2013-6674 [MEDIUM] CWE-79 CVE-2013-6674: Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.
nvd
CVE-2026-8950P3CRITICALCVSS 9.3fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8950 [CRITICAL] CWE-346 CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2012-0470P3CRITICALCVSS 10.0v5.0v6.0+13 more2012-04-25
CVE-2012-0470 [CRITICAL] CWE-119 CVE-2012-0470: Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Fire
Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly
nvd
CVE-2026-2806P3CRITICALCVSS 9.1fixed in 148.02026-02-24
CVE-2026-2806 [CRITICAL] CWE-908 CVE-2026-2806: Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 an
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2023-0767P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-0767 [HIGH] CVE-2023-0767: An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memor
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2010-3166P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3166 [CRITICAL] CWE-119 CVE-2010-3166: Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before
Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.
nvd
CVE-2023-29541P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29541 [HIGH] CWE-116 CVE-2023-29541: Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be int
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112,
nvdosv
CVE-2016-9900P3HIGHCVSS 7.5fixed in 45.6.0≥ unspecified, < 45.62018-06-11
CVE-2016-9900 [HIGH] CWE-254 CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2024-7520P3HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7520 [HIGH] CWE-843 CVE-2024-7520: A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code ex
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvd