Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 40 of 101
CVE-2015-2724P3CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2724 [CRITICAL] CWE-119 CVE-2015-2724: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2014-1548P3CRITICALCVSS 10.0≤ 24.7v24.0+8 more2014-07-23
CVE-2014-1548 [CRITICAL] CVE-2014-1548: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunde
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-12417P3HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier,
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2012-1975P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1975 [CRITICAL] CWE-416 CVE-2012-1975: Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0,
Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-1973P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1973 [CRITICAL] CWE-416 CVE-2012-1973: Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox b
Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2012-1974P3CRITICALCVSS 10.0fixed in 15.02012-08-29
CVE-2012-1974 [CRITICAL] CWE-416 CVE-2012-1974: Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox befor
Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vect
nvd
CVE-2026-6751P3HIGHCVSS 7.3≥ 140.0, < 140.10.02026-04-21
CVE-2026-6751 [HIGH] CWE-457 CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6753P3HIGHCVSS 7.3≥ 140.0, < 140.10.02026-04-21
CVE-2026-6753 [HIGH] CWE-119 CVE-2026-6753: Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150,
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2025-14325P3HIGHCVSS 7.3fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14325 [HIGH] CWE-843 CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2012-1951P3CRITICALCVSS 10.0v5.0v6.0+15 more2012-07-18
CVE-2012-1951 [CRITICAL] CWE-399 CVE-2012-1951: Use-after-free vulnerability in the nsSMILTimeValueSpec::IsEventBased function in Mozilla Firefox 4.
Use-after-free vulnerability in the nsSMILTimeValueSpec::IsEventBased function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary cod
nvd
CVE-2020-6806P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6806 [HIGH] CWE-125 CVE-2020-6806: By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the en
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvdosv
CVE-2011-2988P3CRITICALCVSS 10.0≤ 5.02011-08-18
CVE-2011-2988 [CRITICAL] CWE-119 CVE-2011-2988: Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox
Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.
nvd
CVE-2026-12324P3HIGHCVSS 7.3fixed in Thunderbird 140.12
CVE-2026-12324 [HIGH] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12324
Mozilla Foundation Security Advisory 2026-61
CVE: CVE-2026-12324
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.12
mozilla
CVE-2013-1719P3CRITICALCVSS 10.0≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1719 [CRITICAL] CWE-119 CVE-2013-1719: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-12389P3HIGHCVSS 8.8fixed in 60.3.0≥ unspecified, < 60.32019-02-28
CVE-2018-12389 [HIGH] CWE-119 CVE-2018-12389: Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. So
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.
nvdosv
CVE-2013-5590P3CRITICALCVSS 10.0≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5590 [CRITICAL] CVE-2013-5590: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary co
nvd
CVE-2012-3964P3CRITICALCVSS 10.0≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3964 [CRITICAL] CWE-399 CVE-2012-3964: Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0,
Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2019-11752P3HIGHCVSS 8.8fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11752 [HIGH] CWE-416 CVE-2019-11752: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvdosv
CVE-2017-7752P3HIGHCVSS 8.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7752 [HIGH] CWE-416 CVE-2017-7752: A use-after-free vulnerability during specific user interactions with the input method editor (IME)
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-7846P3HIGHCVSS 8.8fixed in 52.5.2≥ unspecified, < 52.5.22018-06-11
CVE-2017-7846 [HIGH] CWE-74 CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
nvdosv