cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 39 of 101
CVE-2018-12362P3HIGHCVSS 8.8fixed in 52.9≥ 52.9.1, < 60.0+2 more2018-10-18
CVE-2018-12362 [HIGH] CWE-190 CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Ext An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvdosv
CVE-2024-10466P3HIGHCVSS 7.5fixed in 128.4.0≥ 129.0, < 132.0+2 more2024-10-29
CVE-2024-10466 [HIGH] CWE-400 CVE-2024-10466: By sending a specially crafted push message, a remote server could have hung the parent process, cau By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2026-4686P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4686 [HIGH] CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4685P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4685 [HIGH] CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2009-2463P3CRITICALCVSS 10.0v2.0.0.0v2.0.0.1+19 more2009-07-22
CVE-2009-2463 [CRITICAL] CWE-189 CVE-2009-2463: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/l Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspec
nvd
CVE-2023-3417P3HIGHCVSS 7.5fixed in 102.13.1≥ 115.0, < 115.0.1+2 more2023-07-24
CVE-2023-3417 [HIGH] CVE-2023-3417: Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
nvdosv
CVE-2026-6746P3HIGHCVSS 7.5fixed in 140.10.02026-04-21
CVE-2026-6746 [HIGH] CWE-416 CVE-2026-6746: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firef Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-8949P3HIGHCVSS 7.5fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8949 [HIGH] CWE-190 CVE-2026-8949: Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefo Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-4707P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4707 [HIGH] CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2010-3778P3CRITICALCVSS 9.3≤ 3.0.10v0.1+73 more2010-12-10
CVE-2010-3778 [CRITICAL] CWE-119 CVE-2010-3778: Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and Sea Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and SeaMonkey before 2.0.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-8946P3HIGHCVSS 7.5fixed in 140.112026-05-19
CVE-2026-8946 [HIGH] CWE-119 CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-8954P3HIGHCVSS 7.5fixed in 140.112026-05-19
CVE-2026-8954 [HIGH] CWE-119 CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-6749P3HIGHCVSS 7.5fixed in 140.10.02026-04-21
CVE-2026-6749 [HIGH] CWE-908 CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnera Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6759P3HIGHCVSS 7.5≥ 140.0, < 140.10.02026-04-21
CVE-2026-6759 [HIGH] CWE-416 CVE-2026-6759: Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2018-12360P3HIGHCVSS 8.8fixed in 52.9≥ 52.9.1, < 60.0+2 more2018-10-18
CVE-2018-12360 [HIGH] CWE-416 CVE-2018-12360: A use-after-free vulnerability can occur when deleting an input element during a mutation event hand A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvdosv
CVE-2025-14327P3HIGHCVSS 7.5fixed in 146.02025-12-09
CVE-2025-14327 [HIGH] CWE-290 CVE-2025-14327: Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunde Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.
nvdosv
CVE-2026-4684P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4684 [HIGH] CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component Race condition, use-after-free in the Graphics: WebRender component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-16400P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16400 [HIGH] CWE-200 CVE-2026-16400: Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 a Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2016-1974P3HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1974 [HIGH] CWE-119 CVE-2016-1974: The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x be The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
nvd
CVE-2014-1533P3CRITICALCVSS 10.0≥ 0, < 1:24.6.0+build1-0ubuntu0.14.04.12014-06-11
CVE-2014-1533 [CRITICAL] CVE-2014-1533: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
osv
Mozilla Thunderbird vulnerabilities | cvebase