Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 4 of 101
CVE-2007-3845P3CRITICALCVSS 9.3PoCv2.0.0.52007-08-08
CVE-2007-3845 [CRITICAL] CVE-2007-3845: Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey be
Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still po
nvd
CVE-2023-6856P2HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6856 [HIGH] CWE-787 CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on syst
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2019-9816P3MEDIUMCVSS 5.9PoCfixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9816 [MEDIUM] CWE-843 CVE-2019-9816: A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbi
nvdosv
CVE-2022-2200P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-2200 [HIGH] CWE-1321 CVE-2022-2200: If an object prototype was corrupted by an attacker, they would have been able to set undesired attr
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2007-0009P3MEDIUMCVSS 6.8fixed in 1.5.0.102007-02-26
CVE-2007-0009 [MEDIUM] CWE-119 CVE-2007-0009: Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Mas
nvd
CVE-2004-0648P3CRITICALCVSS 10.0PoC≤ 0.7.22004-08-06
CVE-2004-0648 [CRITICAL] CVE-2004-0648: Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attack
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
nvd
CVE-2006-4253P3HIGHCVSS 7.6PoC≥ 0, < 1.5.0.7-12006-08-21
CVE-2006-4253 [HIGH] CVE-2006-4253: Concurrency vulnerability in Mozilla Firefox 1
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxd
osv
CVE-2014-1512P3CRITICALCVSS 10.0fixed in 24.42014-03-19
CVE-2014-1512 [CRITICAL] CWE-416 CVE-2014-1512: Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox bef
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper
nvd
CVE-2006-0884P3CRITICALCVSS 9.3PoC≤ 1.0.7v0.1+16 more2006-02-24
CVE-2006-0884 [CRITICAL] CWE-20 CVE-2006-0884: The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows us
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
nvdosv
CVE-2025-4918P3CRITICALCVSS 9.8fixed in 128.10.2≥ 138.0, < 138.0.22025-05-17
CVE-2025-4918 [CRITICAL] CWE-125 CVE-2025-4918: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. Thi
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
nvdosv
CVE-2026-16367P3CRITICALCVSS 10.0fixed in 153.02026-07-21
CVE-2026-16367 [CRITICAL] CWE-119 CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability wa
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2018-18505P3CRITICALCVSS 10.0fixed in 60.5.02019-02-05
CVE-2018-18505 [CRITICAL] CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authenti
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later chann
nvdosv
CVE-2024-8381P3CRITICALCVSS 9.8≥ unspecified, < 128.2≥ unspecified, < 115.152024-09-03
CVE-2024-8381 [CRITICAL] CWE-843 CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an ob
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
nvdosv
CVE-2021-38503P3CRITICALCVSS 10.0fixed in 91.3≥ unspecified, < 91.32021-12-08
CVE-2021-38503 [CRITICAL] CWE-863 CVE-2021-38503: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypas
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2026-4688P3CRITICALCVSS 10.0≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4688 [CRITICAL] CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-2768P3CRITICALCVSS 10.0fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2768 [CRITICAL] CWE-284 CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Fir
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-0881P3CRITICALCVSS 10.0fixed in 147.02026-01-13
CVE-2026-0881 [CRITICAL] CWE-284 CVE-2026-0881: Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Th
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2026-16383P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16383 [CRITICAL] CWE-693 CVE-2026-16383: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Fir
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16360P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16360 [CRITICAL] CWE-119 CVE-2026-16360: Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these
Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and
nvdmozilla
CVE-2026-16361P3CRITICALCVSS 9.8fixed in 140.13.02026-07-21
CVE-2026-16361 [CRITICAL] CWE-119 CVE-2026-16361: Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory c
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
nvdmozilla