cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 34 of 101
CVE-2026-16354P3HIGHCVSS 7.5fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16354 [HIGH] CWE-200 CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-7320P3HIGHCVSS 7.5fixed in 140.10.1fixed in 150.0.12026-04-28
CVE-2026-7320 [HIGH] CWE-119 CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulne Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
nvdmozilla
CVE-2026-16374P3HIGHCVSS 7.5fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16374 [HIGH] CWE-200 CVE-2026-16374: Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firef Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16391P3HIGHCVSS 7.5fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16391 [HIGH] CWE-200 CVE-2026-16391: Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16384P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16384 [HIGH] CWE-908 CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerabi Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16386P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16386 [HIGH] CWE-908 CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerabi Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16385P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16385 [HIGH] CWE-908 CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerabi Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16378P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16378 [HIGH] CWE-20 CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Fire Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-6772P3HIGHCVSS 7.5fixed in 140.10.02026-04-21
CVE-2026-6772 [HIGH] CWE-754 CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Fir Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6766P3HIGHCVSS 7.5fixed in 140.10.02026-04-21
CVE-2026-6766 [HIGH] CWE-754 CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Fir Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-12314P3HIGHCVSS 7.5fixed in Thunderbird 140.12
CVE-2026-12314 [HIGH] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12314 Mozilla Foundation Security Advisory 2026-61 CVE: CVE-2026-12314 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.12
mozilla
CVE-2026-12312P3HIGHCVSS 7.5fixed in Thunderbird 152
CVE-2026-12312 [HIGH] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12312 Mozilla Foundation Security Advisory 2026-60 CVE: CVE-2026-12312 Product: Thunderbird Impact: high Fixed in: Thunderbird 152
mozilla
CVE-2026-12310P3HIGHCVSS 7.5fixed in Thunderbird 140.12
CVE-2026-12310 [HIGH] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12310 Mozilla Foundation Security Advisory 2026-61 CVE: CVE-2026-12310 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.12
mozilla
CVE-2015-4509P3HIGHCVSS 7.5≥ 0, < 1:38.3.0+build1-0ubuntu0.14.04.12015-09-22
CVE-2015-4509 [HIGH] CVE-2015-4509: Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41 Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via crafted JavaScript code that modifies the URI table of a media element, aka ZDI-CAN-3176.
osv
CVE-2008-0304P3HIGHCVSS 7.5≤ 2.0.0.92008-02-29
CVE-2008-0304 [HIGH] CWE-119 CVE-2008-0304: Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might a Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
nvd
CVE-2013-1676P3CRITICALCVSS 10.0≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1676 [CRITICAL] CWE-119 CVE-2013-1676: The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x befo The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-1976P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1976 [CRITICAL] CWE-416 CVE-2012-1976: Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firef Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecif
nvd
CVE-2012-1972P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1972 [CRITICAL] CWE-416 CVE-2012-1972: Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Fire Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2015-2740P3CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2740 [CRITICAL] CWE-119 CVE-2015-2740: Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39. Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
nvdosv
CVE-2025-14332P3HIGHCVSS 7.3fixed in 146.02025-12-09
CVE-2025-14332 [HIGH] CWE-787 CVE-2025-14332: Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
nvd
Mozilla Thunderbird vulnerabilities | cvebase