cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 22 of 101
CVE-2026-6750P3HIGHCVSS 8.8fixed in 140.10.02026-04-21
CVE-2026-6750 [HIGH] CWE-269 CVE-2026-6750: Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1 Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-8952P3HIGHCVSS 8.8fixed in 151.0.02026-05-19
CVE-2026-8952 [HIGH] CWE-269 CVE-2026-8952: Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 15 Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-6769P3HIGHCVSS 8.8fixed in 140.10.02026-04-21
CVE-2026-6769 [HIGH] CWE-269 CVE-2026-6769: Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6761P3HIGHCVSS 8.8fixed in 140.10.02026-04-21
CVE-2026-6761 [HIGH] CWE-269 CVE-2026-6761: Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firef Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2014-1555P3CRITICALCVSS 9.3≤ 24.6v24.0+7 more2014-07-23
CVE-2014-1555 [CRITICAL] CVE-2014-1555: Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
nvdosv
CVE-2018-12392P3CRITICALCVSS 9.8fixed in 60.3.0≥ unspecified, < 60.32019-02-28
CVE-2018-12392 [CRITICAL] CVE-2018-12392: When manipulating user events in nested loops while opening a document through script, it is possibl When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
nvdosv
CVE-2012-1953P3CRITICALCVSS 9.3v5.0v6.0+15 more2012-07-18
CVE-2012-1953 [CRITICAL] CWE-119 CVE-2012-1953: The ElementAnimations::EnsureStyleRuleFor function in Mozilla Firefox 4.x through 13.0, Firefox ESR The ElementAnimations::EnsureStyleRuleFor function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (buffer over-read, incorrect pointer dereference, and heap-based buffer overflow) or po
nvd
CVE-2024-2612P3HIGHCVSS 8.1fixed in 115.9≥ unspecified, < 115.92024-03-19
CVE-2024-2612 [HIGH] CWE-416 CVE-2024-2612: If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have tri If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
CVE-2024-3864P3HIGHCVSS 8.1fixed in 115.10.0≥ unspecified, < 115.102024-04-16
CVE-2024-3864 [HIGH] CWE-119 CVE-2024-3864: Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2025-4091P3HIGHCVSS 8.1fixed in 128.10.0fixed in 138.02025-04-29
CVE-2025-4091 [HIGH] CWE-119 CVE-2025-4091: Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9 Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbi
nvdosv
CVE-2025-4093P3HIGHCVSS 8.1fixed in 128.10.02025-04-29
CVE-2025-4093 [HIGH] CWE-119 CVE-2025-4093: Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of m Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.10 and Thunderbird 128.10.
nvdosv
CVE-2025-6435P3HIGHCVSS 8.1fixed in 140.02025-06-24
CVE-2025-6435 [HIGH] CWE-434 CVE-2025-6435: If a user saved a response from the Network tab in Devtools using the Save As context menu option, t If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvdosv
CVE-2008-4070P3CRITICALCVSS 10.0≤ 2.0.0.16v0.1+49 more2008-09-27
CVE-2008-4070 [CRITICAL] CWE-119 CVE-2008-4070: Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
nvd
CVE-2023-4050P3HIGHCVSS 7.5≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4050 [HIGH] CVE-2023-4050: In some cases, an untrusted input stream was copied to a stack buffer without checking its size In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2014-1529P3HIGHCVSS 8.8fixed in 24.52014-04-30
CVE-2014-1529 [HIGH] CWE-269 CVE-2014-1529: The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird b The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.
nvdosv
CVE-2023-5176P3CRITICALCVSS 9.8fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5176 [CRITICAL] CWE-787 CVE-2023-5176: Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these b Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvdosv
CVE-2022-31737P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31737 [CRITICAL] CWE-787 CVE-2022-31737: A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdosv
CVE-2025-1020P3CRITICALCVSS 9.8≥ 131.0, < 135.02025-02-04
CVE-2025-1020 [CRITICAL] CWE-787 CVE-2025-1020: Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2018-17466P3HIGHCVSS 8.8≥ 0, < 1:60.4.0-12018-11-14
CVE-2018-17466 [HIGH] CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 70 Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
osv
CVE-2013-0767P3CRITICALCVSS 10.0fixed in 17.0.22013-01-13
CVE-2013-0767 [CRITICAL] CWE-125 CVE-2013-0767: The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x b The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read)
nvd
Mozilla Thunderbird vulnerabilities | cvebase