Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 25 of 101
CVE-2012-3969P3CRITICALCVSS 9.3≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3969 [CRITICAL] CWE-189 CVE-2012-3969: Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Fi
Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via a crafted SVG filter that triggers an incorrect sum calculation, leading to a he
nvd
CVE-2009-1841P3CRITICALCVSS 9.3≤ 2.0.0.19v0.1+65 more2009-06-12
CVE-2009-1841 [CRITICAL] CWE-94 CVE-2009-1841: js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.
js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
nvd
CVE-2026-4687P3HIGHCVSS 8.6≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4687 [HIGH] CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component
Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2012-1958P3CRITICALCVSS 9.3v5.0v6.0+15 more2012-07-18
CVE-2012-1958 [CRITICAL] CWE-399 CVE-2012-1958: Use-after-free vulnerability in the nsGlobalWindow::PageHidden function in Mozilla Firefox 4.x throu
Use-after-free vulnerability in the nsGlobalWindow::PageHidden function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 might allow remote attackers to execute arbitrary code via vectors related to focused content.
nvd
CVE-2010-3180P3CRITICALCVSS 9.3≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3180 [CRITICAL] CWE-399 CVE-2010-3180: Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x be
Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessing the locationbar property of a closed window.
nvd
CVE-2025-6432P3HIGHCVSS 8.6≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6432 [HIGH] CVE-2025-6432: When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140 and Thunderbird < 140.
osv
CVE-2013-0745P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0745 [CRITICAL] CWE-94 CVE-2013-0745: The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunder
The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly interact with garbage collection, which allows remote attackers to execute arbitrary code via a crafted HTML document referencing JavaScript objects.
nvd
CVE-2012-1946P3CRITICALCVSS 9.3v5.0v6.0+14 more2012-06-05
CVE-2012-1946 [CRITICAL] CWE-399 CVE-2012-1946: Use-after-free vulnerability in the nsINode::ReplaceOrInsertBefore function in Mozilla Firefox 4.x t
Use-after-free vulnerability in the nsINode::ReplaceOrInsertBefore function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 might allow remote attackers to execute arbitrary code via document changes involving replacement or insertion of
nvd
CVE-2017-5460P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5460 [CRITICAL] CWE-416 CVE-2017-5460: A use-after-free vulnerability in frame selection triggered by a combination of malicious script con
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2014-1564P4MEDIUMCVSS 4.3PoCv31.02014-09-03
CVE-2014-1564 [MEDIUM] CWE-824 CVE-2014-1564: Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not p
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.
nvdosv
CVE-2010-2760P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2760 [CRITICAL] CVE-2010-2760: Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.
Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue ex
nvd
CVE-2024-1553P3HIGHCVSS 8.1fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1553 [HIGH] CWE-119 CVE-2024-1553: Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these b
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvdosv
CVE-2012-1952P3CRITICALCVSS 9.3v5.0v6.0+15 more2012-07-18
CVE-2012-1952 [CRITICAL] CWE-399 CVE-2012-1952: The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before
The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly perform a cast of a frame variable during processing of mixed row-group and column-group frames, which might allow remote attackers
nvd
CVE-2012-0478P3CRITICALCVSS 9.3v5.0v6.0+13 more2012-04-25
CVE-2012-0478 [CRITICAL] CWE-264 CVE-2012-0478: The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ES
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
nvd
CVE-2009-2535P4MEDIUMCVSS 5.0PoC≤ 2.0.0.18v0.1+65 more2009-07-20
CVE-2009-2535 [MEDIUM] CVE-2009-2535: Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attack
Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
nvd
CVE-2025-5269P3HIGHCVSS 8.1fixed in 128.11.02025-05-27
CVE-2025-5269 [HIGH] CWE-787 CVE-2025-5269: Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.11 and Thunderbird 128.11.
nvdosv
CVE-2019-9796P3CRITICALCVSS 9.8fixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9796 [CRITICAL] CWE-416 CVE-2019-9796: A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers wi
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array.
nvdosv
CVE-2026-8969P3HIGHCVSS 8.1fixed in 151.0.02026-05-19
CVE-2026-8969 [HIGH] CWE-693 CVE-2026-8969: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Th
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2013-0764P3CRITICALCVSS 9.3fixed in 17.0.32013-01-13
CVE-2013-0764 [CRITICAL] CWE-326 CVE-2013-0764: The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x befo
The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thread safety for SSL sessions, which allows remote attackers to execute arbitrary code via crafted data, as demonstrated by e-mail mes
nvd
CVE-2019-9790P3CRITICALCVSS 9.8≤ 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9790 [CRITICAL] CWE-416 CVE-2019-9790: A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained u
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvdosv