Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 44 of 101
CVE-2024-1936P3HIGHCVSS 7.5fixed in 115.8.1≥ unspecified, < 115.8.12024-03-04
CVE-2024-1936 [HIGH] CWE-922 CVE-2024-1936: The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitr
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message cont
nvdosv
CVE-2024-3852P3HIGHCVSS 7.5fixed in 115.10≥ unspecified, < 115.102024-04-16
CVE-2024-3852 [HIGH] CWE-386 CVE-2024-3852: GetBoundName could return the wrong version of an object when JIT optimizations were applied. This v
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2024-10459P3HIGHCVSS 7.5fixed in 128.4.0≥ 129.0, < 132.0+2 more2024-10-29
CVE-2024-10459 [HIGH] CWE-416 CVE-2024-10459: An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentia
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2026-6758P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6758 [HIGH] CWE-416 CVE-2026-6758: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-4709P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4709 [HIGH] CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4706P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4706 [HIGH] CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2025-13016P3HIGHCVSS 7.5≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13016 [HIGH] CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2013-5616P3CRITICALCVSS 9.8fixed in 24.22013-12-11
CVE-2013-5616 [CRITICAL] CWE-416 CVE-2013-5616: Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla F
Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listen
nvd
CVE-2026-6747P3HIGHCVSS 7.5fixed in 140.10.02026-04-21
CVE-2026-6747 [HIGH] CWE-416 CVE-2026-6747: Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6754P3HIGHCVSS 7.5fixed in 140.10.02026-04-21
CVE-2026-6754 [HIGH] CWE-416 CVE-2026-6754: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Fire
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-12305P3HIGHCVSS 7.5fixed in Thunderbird 140.12
CVE-2026-12305 [HIGH] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12305
Mozilla Foundation Security Advisory 2026-61
CVE: CVE-2026-12305
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.12
mozilla
CVE-2026-8967P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8967 [HIGH] CWE-200 CVE-2026-8967: Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 15
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-8966P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8966 [HIGH] CWE-200 CVE-2026-8966: Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 a
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-8965P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8965 [HIGH] CWE-200 CVE-2026-8965: Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 a
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2015-2725P3CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2725 [CRITICAL] CWE-119 CVE-2015-2725: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2026-8963P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8963 [HIGH] CWE-290 CVE-2026-8963: Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderb
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-8964P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8964 [HIGH] CWE-451 CVE-2026-8964: Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thund
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2006-0748P3CRITICALCVSS 9.3v1.0v1.0.1+8 more2006-04-14
CVE-2006-0748 [CRITICAL] CWE-399 CVE-2006-0748: Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.
Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.
nvdosv
CVE-2026-2783P3HIGHCVSS 7.5fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2783 [HIGH] CWE-843 CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulne
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2024-6603P3HIGHCVSS 7.4fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosv