Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 38 of 101
CVE-2017-7756P3CRITICALCVSS 9.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7756 [CRITICAL] CWE-416 CVE-2017-7756: A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Req
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2023-25734P3HIGHCVSS 8.1fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25734 [HIGH] CWE-601 CVE-2023-25734: After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability
nvd
CVE-2025-1943P3HIGHCVSS 8.2fixed in 136.02025-03-04
CVE-2025-1943 [HIGH] CWE-122 CVE-2025-1943: Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
nvdosv
CVE-2019-11709P3CRITICALCVSS 9.8fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11709 [CRITICAL] CWE-787 CVE-2019-11709: Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 6
nvdosv
CVE-2013-0775P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0775 [CRITICAL] CWE-416 CVE-2013-0775: Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firef
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.
nvd
CVE-2006-1728P3CRITICALCVSS 9.3≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1728 [CRITICAL] CVE-2006-1728: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
nvdosv
CVE-2012-3989P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3989 [CRITICAL] CWE-119 CVE-2012-3989: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perf
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.
nvd
CVE-2019-11713P3CRITICALCVSS 9.8fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11713 [CRITICAL] CWE-416 CVE-2019-11713: A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still
A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2025-1932P3HIGHCVSS 8.1≥ ], < 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1932 [HIGH] CWE-125 CVE-2025-1932: An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-o
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2025-11713P3HIGHCVSS 8.1fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11713 [HIGH] CWE-116 CVE-2025-11713: Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into execut
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvdosv
CVE-2009-1392P3CRITICALCVSS 9.3≤ 2.0.0.19v0.1+65 more2009-06-12
CVE-2009-1392 [CRITICAL] CWE-94 CVE-2009-1392: The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey be
The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) Unhoo
nvd
CVE-2020-12393P3HIGHCVSS 7.8fixed in 68.8.0≥ unspecified, < 68.8.02020-05-26
CVE-2020-12393 [HIGH] CWE-78 CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows
nvd
CVE-2025-13017P3HIGHCVSS 8.1≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13017 [HIGH] CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2025-13019P3HIGHCVSS 8.1≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13019 [HIGH] CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component
Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2020-6825P3CRITICALCVSS 9.8fixed in 68.7.0≥ unspecified, < 68.7.02020-04-24
CVE-2020-6825 [CRITICAL] CWE-787 CVE-2020-6825: Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bug
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0
nvdosv
CVE-2025-14322P3HIGHCVSS 8.0fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14322 [HIGH] CWE-754 CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vul
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2017-7804P3HIGHCVSS 7.5fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7804 [HIGH] CWE-20 CVE-2017-7804: The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this situation. Note: This attack only affects Windows operating systems. Other operating
nvd
CVE-2016-1521P3HIGHCVSS 8.8≤ 38.5.12016-02-13
CVE-2016-1521 [HIGH] CWE-119 CVE-2016-1521: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla F
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application cras
nvd
CVE-2025-0241P3HIGHCVSS 7.7fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0241 [HIGH] CWE-401 CVE-2025-0241: When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially e
When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2010-3776P3CRITICALCVSS 9.3≤ 3.0.10v0.1+76 more2010-12-10
CVE-2010-3776 [CRITICAL] CWE-119 CVE-2010-3776: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd