Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 19 of 101
CVE-2014-1509P3HIGHCVSS 8.8fixed in 24.42014-03-19
CVE-2014-1509 [HIGH] CWE-120 CVE-2014-1509: Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox b
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.
nvd
CVE-2012-0444P3CRITICALCVSS 10.0fixed in 3.1.18≥ 5.0, < 10.02012-02-01
CVE-2012-0444 [CRITICAL] CWE-119 CVE-2012-0444: Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, an
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
nvd
CVE-2019-11693P3CRITICALCVSS 9.8fixed in 60.7.0≥ unspecified, < 60.72019-07-23
CVE-2019-11693 [CRITICAL] CWE-787 CVE-2019-11693: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers o
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox <
nvdosv
CVE-2025-3030P3HIGHCVSS 8.1fixed in 128.8.0≥ 129.0, < 136.02025-04-01
CVE-2025-3030 [HIGH] CWE-416 CVE-2025-3030: Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and Thunderbir
nvdosv
CVE-2025-5268P3HIGHCVSS 8.1fixed in 128.11.0≥ 129.0, < 139.02025-05-27
CVE-2025-5268 [HIGH] CWE-119 CVE-2025-5268: Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunder
nvdosv
CVE-2026-12326P3HIGHCVSS 8.1fixed in 152.0.02026-06-16
CVE-2026-12326 [HIGH] CWE-119 CVE-2026-12326: Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2026-8093P3HIGHCVSS 8.1fixed in 150.0.22026-05-07
CVE-2026-8093 [HIGH] CWE-119 CVE-2026-8093: Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corrupti
Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.
nvdmozilla
CVE-2019-11692P3CRITICALCVSS 9.8fixed in 60.7.0≥ unspecified, < 60.72019-07-23
CVE-2019-11692 [CRITICAL] CWE-416 CVE-2019-11692: A use-after-free vulnerability can occur when listeners are removed from the event listener manager
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
CVE-2023-5730P3CRITICALCVSS 9.8fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5730 [CRITICAL] CWE-787 CVE-2023-5730: Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these b
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2018-5104P3CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5104 [CRITICAL] CWE-416 CVE-2018-5104: A use-after-free vulnerability can occur during font face manipulation when a font face is freed whi
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2018-5102P3CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5102 [CRITICAL] CWE-416 CVE-2018-5102: A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, r
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2022-34470P3CRITICALCVSS 9.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34470 [CRITICAL] CWE-416 CVE-2022-34470: Session history navigations may have led to a use-after-free and potentially exploitable crash. This
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2022-31736P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31736 [CRITICAL] CWE-942 CVE-2022-31736: A malicious website could have learned the size of a cross-origin resource that supported Range requ
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdosv
CVE-2023-29531P3CRITICALCVSS 9.8fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29531 [CRITICAL] CWE-787 CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory cor
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash.
*This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
nvd
CVE-2023-4056P3CRITICALCVSS 9.8≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4056 [CRITICAL] CVE-2023-4056: Memory safety bugs present in Firefox 115, Firefox ESR 115
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2022-46882P3CRITICALCVSS 9.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46882 [CRITICAL] CWE-416 CVE-2022-46882: A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnera
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvdosv
CVE-2024-3863P3CRITICALCVSS 9.8fixed in 115.10≥ unspecified, < 115.102024-04-16
CVE-2024-3863 [CRITICAL] CWE-434 CVE-2024-3863: The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue on
The executable file warning was not presented when downloading .xrm-ms files.
*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-9394P3HIGHCVSS 7.5fixed in 128.3v129.0+2 more2024-10-01
CVE-2024-9394 [HIGH] CWE-79 CVE-2024-9394: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This
nvdosv
CVE-2024-6611P3CRITICALCVSS 9.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6611 [CRITICAL] CWE-1275 CVE-2024-6611: A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2024-9393P3HIGHCVSS 7.5fixed in 128.3v129.0+2 more2024-10-01
CVE-2024-9393 [HIGH] CWE-346 CVE-2024-9393: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vu
nvdosv