Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 18 of 101
CVE-2025-1011P3HIGHCVSS 8.8fixed in 135.0≥ 128.0.1, < 128.7.02025-02-04
CVE-2025-1011 [HIGH] CWE-94 CVE-2025-1011: A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an at
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2024-8382P3HIGHCVSS 8.8≥ unspecified, < 128.2≥ unspecified, < 115.152024-09-03
CVE-2024-8382 [HIGH] CWE-273 CVE-2024-8382: Internal browser event interfaces were exposed to web content when privileged EventHandler listener
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools consol
nvdosv
CVE-2012-3990P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3990 [CRITICAL] CWE-416 CVE-2012-3990: Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0,
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the nsIContent::GetNameSpaceID function.
nvd
CVE-2026-2769P3HIGHCVSS 8.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2769 [HIGH] CWE-416 CVE-2026-2769: Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Fir
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-0882P3HIGHCVSS 8.8fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0882 [HIGH] CWE-416 CVE-2026-0882: Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32
Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2026-8955P3HIGHCVSS 8.8fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8955 [HIGH] CWE-269 CVE-2026-8955: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Fir
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-12291P3HIGHCVSS 8.8fixed in 140.12.0fixed in 152.0.02026-06-16
CVE-2026-12291 [HIGH] CWE-416 CVE-2026-12291: Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firef
Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2025-14323P3HIGHCVSS 8.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14323 [HIGH] CVE-2025-14323: Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 14
Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2026-8972P3HIGHCVSS 8.8fixed in 151.0.02026-05-19
CVE-2026-8972 [HIGH] CWE-269 CVE-2026-8972: Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 1
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-8970P3HIGHCVSS 8.8fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8970 [HIGH] CWE-269 CVE-2026-8970: Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2024-5696P3HIGHCVSS 8.6fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5696 [HIGH] CWE-787 CVE-2024-5696: By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory lea
By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvdosv
CVE-2014-1482P3HIGHCVSS 8.8fixed in 24.32014-02-06
CVE-2014-1482 [HIGH] CWE-787 CVE-2014-1482: RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
nvd
CVE-2025-13014P3HIGHCVSS 8.8≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13014 [HIGH] CVE-2025-13014: Use-after-free in the Audio/Video component
Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2026-16379P3HIGHCVSS 8.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16379 [HIGH] CWE-269 CVE-2026-16379: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2025-13020P3HIGHCVSS 8.8≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13020 [HIGH] CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component
Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2013-1735P3CRITICALCVSS 9.3≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1735 [CRITICAL] CWE-20 CVE-2013-1735: Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox b
Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.
nvd
CVE-2012-3962P3CRITICALCVSS 9.3≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3962 [CRITICAL] CVE-2012-3962: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ES
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2026-8958P3HIGHCVSS 8.6fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8958 [HIGH] CWE-668 CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerabi
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2014-1513P3HIGHCVSS 8.8fixed in 24.42014-03-19
CVE-2014-1513 [HIGH] CWE-787 CVE-2014-1513: TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird befor
TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted we
nvd
CVE-2012-5835P3CRITICALCVSS 10.0fixed in 17.02012-11-21
CVE-2012-5835 [CRITICAL] CWE-190 CVE-2012-5835: Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0
Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via crafted data.
nvd