Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 48 of 101
CVE-2016-5290P3CRITICALCVSS 9.8fixed in 45.5.0≥ unspecified, < 45.52018-06-11
CVE-2016-5290 [CRITICAL] CWE-119 CVE-2016-5290: Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvdosv
CVE-2018-5183P3CRITICALCVSS 9.8fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5183 [CRITICAL] CWE-119 CVE-2018-5183: Mozilla developers backported selected changes in the Skia library. These changes correct memory cor
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvdosv
CVE-2013-0780P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0780 [CRITICAL] CWE-416 CVE-2013-0780: Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefo
Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a craft
nvd
CVE-2014-1531P3HIGHCVSS 8.8fixed in 24.52014-04-30
CVE-2014-1531 [HIGH] CWE-416 CVE-2014-1531: Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that i
nvdosv
CVE-2017-5440P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5440 [CRITICAL] CWE-416 CVE-2017-5440: A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 5
nvd
CVE-2018-5145P3CRITICALCVSS 9.8fixed in 52.7.0≥ unspecified, < 52.72018-06-11
CVE-2018-5145 [CRITICAL] CWE-119 CVE-2018-5145: Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruptio
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvdosv
CVE-2017-7810P3CRITICALCVSS 9.8fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7810 [CRITICAL] CWE-119 CVE-2017-7810: Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvdosv
CVE-2017-5454P3HIGHCVSS 7.5fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5454 [HIGH] CWE-200 CVE-2017-5454: A mechanism to bypass file system access protections in the sandbox to use the file picker to access
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2017-7809P3CRITICALCVSS 9.8fixed in 52.3.02018-06-11
CVE-2017-7809 [CRITICAL] CWE-416 CVE-2017-7809: A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2012-1971P3CRITICALCVSS 9.3≤ 14.0v1.0+98 more2012-08-29
CVE-2012-1971 [CRITICAL] CVE-2012-1971: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown
nvd
CVE-2022-3033P3HIGHCVSS 8.1fixed in 91.13.1≥ 102.0, < 102.2.1+1 more2022-12-22
CVE-2022-3033 [HIGH] CWE-79 CVE-2022-3033: If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <
If a Thunderbird user replied to a crafted HTML email containing a meta tag, with the meta tag having the http-equiv="refresh" attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attribut
nvdosv
CVE-2015-2735P3CRITICALCVSS 9.3≤ 38.0.12015-07-06
CVE-2015-2735 [CRITICAL] CWE-17 CVE-2015-2735: nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1,
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvdosv
CVE-2004-0904P3CRITICALCVSS 10.0v0.6v0.7+3 more2004-12-31
CVE-2004-0904 [CRITICAL] CVE-2004-0904: Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
nvd
CVE-2013-1720P3MEDIUMCVSS 6.8≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1720 [MEDIUM] CWE-119 CVE-2013-1720: The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox
The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffe
nvd
CVE-2016-2805P3MEDIUMCVSS 6.5≥ 0, < 1:38.8.0+build1-0ubuntu0.14.04.1≥ 0, < 1:38.8.0+build1-0ubuntu0.16.04.12016-05-19
CVE-2016-2805 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect r
osv
CVE-2025-10534P3HIGHCVSS 8.1fixed in 143.02025-09-16
CVE-2025-10534 [HIGH] CWE-79 CVE-2025-10534: Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Th
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-8030P3HIGHCVSS 8.1fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8030 [HIGH] CWE-94 CVE-2025-8030: Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into e
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvdosv
CVE-2026-0878P3HIGHCVSS 8.0fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0878 [HIGH] CWE-20 CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vul
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2017-5413P3CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5413 [CRITICAL] CWE-119 CVE-2017-5413: A segmentation fault can occur during some bidirectional layout operations. This vulnerability affec
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2008-2811P3CRITICALCVSS 10.0≤ 2.0.0.14v2.0.0.0+11 more2008-07-07
CVE-2008-2811 [CRITICAL] CWE-399 CVE-2008-2811: The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.
nvd