Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 20 of 101
CVE-2024-9402P3CRITICALCVSS 9.8fixed in 128.3.0≥ 129.0, < 131.0+2 more2024-10-01
CVE-2024-9402 [CRITICAL] CWE-119 CVE-2024-9402: Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvdosv
CVE-2024-8387P3CRITICALCVSS 9.8v128.1≥ unspecified, < 128.22024-09-03
CVE-2024-8387 [CRITICAL] CWE-787 CVE-2024-8387: Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these b
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvdosv
CVE-2018-12368P3HIGHCVSS 8.1fixed in 52.9≥ unspecified, < 60+1 more2018-10-18
CVE-2018-12368 [HIGH] CVE-2018-12368: Windows 10 does not warn users before opening executable files with the SettingContent-ms extension
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open per
nvd
CVE-2021-43529P3CRITICALCVSS 9.8fixed in 91.3.02023-02-16
CVE-2021-43529 [CRITICAL] CVE-2021-43529: Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
nvdosv
CVE-2025-8044P3CRITICALCVSS 9.8fixed in 141.02025-07-22
CVE-2025-8044 [CRITICAL] CWE-119 CVE-2025-8044: Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141 and Thunderbird 141.
nvd
CVE-2026-2805P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2805 [CRITICAL] CWE-824 CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and T
Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-2800P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2800 [CRITICAL] CWE-290 CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2015-2731P3CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2731 [CRITICAL] CVE-2015-2731: Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation
Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.
nvdosv
CVE-2025-6433P3CRITICALCVSS 9.8≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6433 [CRITICAL] CVE-2025-6433: If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the u
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability
osv
CVE-2025-8038P3CRITICALCVSS 9.8fixed in 140.1.0fixed in 141.02025-07-22
CVE-2025-8038 [CRITICAL] CWE-345 CVE-2025-8038: Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability w
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvdosv
CVE-2026-8959P3CRITICALCVSS 9.6fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8959 [CRITICAL] CWE-20 CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerabili
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2012-3966P3CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3966 [CRITICAL] CWE-119 CVE-2012-3966: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ES
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a negative height value in a BMP image within a .ICO file, related to (1) improper handling of the tr
nvd
CVE-2019-11759P3HIGHCVSS 8.8fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11759 [HIGH] CWE-120 CVE-2019-11759: An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored o
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvdosv
CVE-2010-3167P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3167 [CRITICAL] CWE-119 CVE-2010-3167: The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer v
nvd
CVE-2013-5604P3CRITICALCVSS 9.3≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5604 [CRITICAL] CWE-119 CVE-2013-5604: The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Fire
The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of s
nvd
CVE-2018-18493P3CRITICALCVSS 9.8fixed in 60.4.0≥ unspecified, < 60.42019-02-28
CVE-2018-18493 [CRITICAL] CWE-119 CVE-2018-18493: A buffer overflow can occur in the Skia library during buffer offset calculations with hardware acce
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvdosv
CVE-2023-6861P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6861 [HIGH] CWE-787 CVE-2023-6861: The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in he
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2025-0242P3MEDIUMCVSS 6.5fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0242 [MEDIUM] CWE-787 CVE-2025-0242: Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, T
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134, Firefox
nvdosv
CVE-2008-1235P3CRITICALCVSS 9.3≤ 2.0.0.12v0.1+31 more2008-03-27
CVE-2008-1235 [CRITICAL] CVE-2008-1235: Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMo
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka "Privilege escalation via incorrect principals."
nvd
CVE-2020-6822P3HIGHCVSS 8.8fixed in 68.7.0≥ unspecified, < 68.7.02020-04-24
CVE-2020-6822 [HIGH] CWE-787 CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvdosv