Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 26 of 101
CVE-2019-9795P3CRITICALCVSS 9.8fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9795 [CRITICAL] CWE-617 CVE-2019-9795: A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvdosv
CVE-2019-9819P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9819 [CRITICAL] CWE-843 CVE-2019-9819: A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API,
A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
CVE-2019-9820P3CRITICALCVSS 9.8fixed in 60.7.0≥ unspecified, < 60.72019-07-23
CVE-2019-9820 [CRITICAL] CWE-416 CVE-2019-9820: A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in
A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
CVE-2012-5830P3HIGHCVSS 8.8fixed in 17.02012-11-21
CVE-2012-5830 [HIGH] CWE-416 CVE-2012-5830: Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunde
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document.
nvd
CVE-2022-45406P3CRITICALCVSS 9.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45406 [CRITICAL] CWE-416 CVE-2022-45406: If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2019-15903P3HIGHCVSS 7.5≥ 0, < 1:68.2.1-12019-09-04
CVE-2019-15903 [HIGH] CVE-2019-15903: In libexpat before 2
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
osv
CVE-2021-4127P3CRITICALCVSS 9.8fixed in 78.9.0≥ unspecified, < 78.92022-12-22
CVE-2021-4127 [CRITICAL] CVE-2021-4127: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be e
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
nvdosv
CVE-2022-31747P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31747 [CRITICAL] CWE-125 CVE-2022-31747: Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memor
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thund
nvdosv
CVE-2023-4057P3CRITICALCVSS 9.8≥ unspecified, < 115.12023-08-01
CVE-2023-4057 [CRITICAL] CWE-787 CVE-2023-4057: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these b
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
nvdosv
CVE-2026-6785P3HIGHCVSS 7.5≥ 140.0, < 140.10.02026-04-26
CVE-2026-6785 [HIGH] CWE-125 CVE-2026-6785: Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox
nvdmozilla
CVE-2017-7845P3HIGHCVSS 8.8fixed in 52.5.2≥ unspecified, < 52.5.22018-06-11
CVE-2017-7845 [HIGH] CWE-119 CVE-2017-7845: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graph
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaf
nvd
CVE-2022-26384P3CRITICALCVSS 9.6fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26384 [CRITICAL] CWE-693 CVE-2022-26384: If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but
If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvdosv
CVE-2025-3032P3HIGHCVSS 7.4fixed in 137.02025-04-01
CVE-2025-3032 [HIGH] CWE-403 CVE-2025-3032: Leaking of file descriptors from the fork server to web content processes could allow for privilege
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvdosv
CVE-2026-4371P3HIGHCVSS 7.4fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4371 [HIGH] CWE-126 CVE-2026-4371: A malicious mail server could send malformed strings with negative lengths, causing the parser to re
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149
nvdosv
CVE-2024-7519P3CRITICALCVSS 9.6fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7519 [CRITICAL] CWE-787 CVE-2024-7519: Insufficient checks when processing graphics shared memory could have led to memory corruption. This
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdosv
CVE-2020-15659P3HIGHCVSS 8.8fixed in 68.11≥ 78.0.1, < 78.1.0+2 more2020-08-10
CVE-2020-15659 [HIGH] CWE-787 CVE-2020-15659: Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,
nvdosv
CVE-2012-3971P3CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3971 [CRITICAL] CWE-119 CVE-2012-3971: Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbir
Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the (1) Silf::readClassMap and (2) Pass::readPass functions.
nvd
CVE-2012-3970P3CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3970 [CRITICAL] CWE-399 CVE-2012-3970: Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, F
Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movemen
nvd
CVE-2020-15673P3HIGHCVSS 8.8fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15673 [HIGH] CWE-416 CVE-2020-15673: Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of t
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvdosv
CVE-2021-23994P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23994 [HIGH] CWE-909 CVE-2021-23994: A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of b
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvdosv