Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 28 of 101
CVE-2023-29550P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29550 [HIGH] CVE-2023-29550: Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.1
nvdosv
CVE-2023-29536P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29536 [HIGH] CWE-416 CVE-2023-29536: An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-con
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvdosv
CVE-2022-0566P3HIGHCVSS 8.8fixed in 91.6.1≥ unspecified, < 91.6.12022-12-22
CVE-2022-0566 [HIGH] CWE-787 CVE-2022-0566: It may be possible for an attacker to craft an email message that causes Thunderbird to perform an o
It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.
nvdosv
CVE-2023-25739P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25739 [HIGH] CWE-416 CVE-2023-25739: Module load requests that failed were not being checked as to whether or not they were cancelled cau
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2024-9396P3HIGHCVSS 8.8fixed in 128.3.0≥ 129.0, < 131.0+2 more2024-10-01
CVE-2024-9396 [HIGH] CWE-119 CVE-2024-9396: It is currently unknown if this issue is exploitable but a condition may arise where the structured
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvdosv
CVE-2008-2785P3CRITICALCVSS 9.3≤ 2.0.0.14v0.1+31 more2008-06-19
CVE-2008-2785 [CRITICAL] CWE-189 CVE-2008-2785: Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey bef
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS objec
nvd
CVE-2018-5188P3CRITICALCVSS 9.8fixed in 52.9≥ unspecified, < 60+1 more2018-10-18
CVE-2018-5188 [CRITICAL] CWE-119 CVE-2018-5188: Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs s
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefo
nvdosv
CVE-2025-1930P3HIGHCVSS 8.8fixed in 128.8fixed in 136.02025-03-04
CVE-2025-1930 [HIGH] CWE-416 CVE-2025-1930: On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a u
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2026-2798P3HIGHCVSS 8.8fixed in 148.02026-02-24
CVE-2026-2798 [HIGH] CWE-416 CVE-2026-2798: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Th
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2025-6426P3HIGHCVSS 8.8≥ 0, < 1:128.12.0+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6426 [HIGH] CVE-2025-6426: The executable file warning did not warn users before opening files with the `terminal` extension
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
osv
CVE-2010-1196P3CRITICALCVSS 9.3≤ 3.0.4v0.1+40 more2010-06-24
CVE-2010-1196 [CRITICAL] CWE-189 CVE-2010-1196: Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x befo
Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.
nvd
CVE-2017-5438P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5438 [CRITICAL] CWE-416 CVE-2017-5438: A use-after-free vulnerability during XSLT processing due to the result handler being held by a free
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2013-0762P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0762 [CRITICAL] CWE-416 CVE-2013-0762: Use-after-free vulnerability in the imgRequest::OnStopFrame function in Mozilla Firefox before 18.0,
Use-after-free vulnerability in the imgRequest::OnStopFrame function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (h
nvd
CVE-2013-0766P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0766 [CRITICAL] CWE-416 CVE-2013-0766: Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0,
Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (hea
nvd
CVE-2017-7818P3CRITICALCVSS 9.8fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7818 [CRITICAL] CWE-416 CVE-2017-7818: A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applic
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvdosv
CVE-2013-0746P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0746 [CRITICAL] CVE-2013-0746: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a den
nvd
CVE-2023-28427P3HIGHCVSS 8.2≥ 0, < 1:102.10.0-1~deb11u1≥ 0, < 1:102.9.1-12023-03-28
CVE-2023-28427 [HIGH] CVE-2023-28427: matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding o
osv
CVE-2017-5443P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5443 [CRITICAL] CWE-787 CVE-2017-5443: An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This v
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2020-15683P3CRITICALCVSS 9.8fixed in 78.4≥ unspecified, < 78.42020-10-22
CVE-2020-15683 [CRITICAL] CWE-416 CVE-2020-15683: Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird <
nvdosv
CVE-2014-1556P3CRITICALCVSS 9.3≤ 24.6v24.0+7 more2014-07-23
CVE-2014-1556 [CRITICAL] CWE-94 CVE-2014-1556: Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
nvdosv