cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 42 of 101
CVE-2023-25746P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25746 [HIGH] CWE-787 CVE-2023-25746: Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corrup Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8.
nvdosv
CVE-2022-31740P3HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31740 [HIGH] CWE-119 CVE-2022-31740: On arm64, WASM code could have resulted in incorrect assembly generation leading to a register alloc On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdosv
CVE-2012-0464P3HIGHCVSS 7.5≥ 1.0, ≤ 3.1.19≤ 10.02012-03-14
CVE-2012-0464 [HIGH] CWE-399 CVE-2012-0464: Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join f
nvd
CVE-2017-5396P3CRITICALCVSS 9.8fixed in 45.7.0≥ unspecified, < 45.72018-06-11
CVE-2017-5396 [CRITICAL] CWE-416 CVE-2017-5396: A use-after-free vulnerability in the Media Decoder when working with media files when some events a A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2024-6609P3HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6609 [HIGH] CVE-2024-6609: When almost out-of-memory an elliptic curve key which was never allocated could have been freed agai When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2013-0795P3CRITICALCVSS 10.0v17.0v17.0.1+3 more2013-04-03
CVE-2013-0795 [CRITICAL] CWE-264 CVE-2013-0795: The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not prevent use of the cloneNode method for cloning a protected node, which allows remote attackers to bypass the Same Origin Policy or possibly exe
nvd
CVE-2025-1014P3HIGHCVSS 8.8≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-1014 [HIGH] CWE-295 CVE-2025-1014: Certificate length was not properly checked when added to a certificate store. In practice only trus Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2017-5398P3CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 52+1 more2018-06-11
CVE-2017-5398 [CRITICAL] CWE-119 CVE-2017-5398: Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory c Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvdosv
CVE-2009-1838P3CRITICALCVSS 9.3≤ 2.0.0.19v0.1+65 more2009-06-12
CVE-2009-1838 [CRITICAL] CWE-94 CVE-2009-1838: The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for th
nvd
CVE-2018-5155P3CRITICALCVSS 9.8fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5155 [CRITICAL] CWE-416 CVE-2018-5155: A use-after-free vulnerability can occur while adjusting layout during SVG animations with text path A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvdosv
CVE-2013-5613P3CRITICALCVSS 9.8fixed in 24.22013-12-11
CVE-2013-5613 [CRITICAL] CWE-416 CVE-2013-5613: Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox be Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related
nvd
CVE-2011-0061P3CRITICALCVSS 9.3≤ 3.1.7v0.1+78 more2011-03-02
CVE-2011-0061 [CRITICAL] CWE-119 CVE-2011-0061: Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey befo Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
nvd
CVE-2010-2767P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2767 [CRITICAL] CWE-399 CVE-2010-2767: The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunde The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via craft
nvd
CVE-2017-7819P3CRITICALCVSS 9.8fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7819 [CRITICAL] CWE-416 CVE-2017-7819: A use-after-free vulnerability can occur in design mode when image objects are resized if objects re A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvdosv
CVE-2017-7826P3CRITICALCVSS 9.8fixed in 52.5.0≥ unspecified, < 52.52018-06-11
CVE-2017-7826 [CRITICAL] CWE-119 CVE-2017-7826: Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evide Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvdosv
CVE-2018-5089P3CRITICALCVSS 9.8fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5089 [CRITICAL] CWE-119 CVE-2018-5089: Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evide Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2020-12387P3HIGHCVSS 8.1fixed in 68.8.0≥ unspecified, < 68.8.02020-05-26
CVE-2020-12387 [HIGH] CWE-362 CVE-2020-12387: A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. Th A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvdosv
CVE-2018-12376P3CRITICALCVSS 9.8fixed in 60.2.1≥ unspecified, < 60.2.12018-10-18
CVE-2018-12376 [CRITICAL] CWE-119 CVE-2018-12376: Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvdosv
CVE-2017-5401P3CRITICALCVSS 9.8fixed in 45.8.0≥ unspecified, < 52+1 more2018-06-11
CVE-2017-5401 [CRITICAL] CWE-388 CVE-2017-5401: A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a l A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2021-29986P3HIGHCVSS 8.1fixed in 78.13.0≥ unspecified, < 78.13+1 more2021-08-17
CVE-2021-29986 [HIGH] CWE-362 CVE-2021-29986: A suspected race condition when calling getaddrinfo led to memory corruption and a potentially explo A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdosv