Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 5 of 101
CVE-2026-16349P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16349 [CRITICAL] CWE-346 CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-4692P3CRITICALCVSS 10.0fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4692 [CRITICAL] CWE-653 CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149,
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdosv
CVE-2026-2776P3CRITICALCVSS 10.0fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2776 [CRITICAL] CWE-119 CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software.
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2761P3CRITICALCVSS 10.0fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2761 [CRITICAL] CWE-693 CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Fi
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2760P3CRITICALCVSS 10.0fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2760 [CRITICAL] CWE-1384 CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulne
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-16351P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16351 [CRITICAL] CWE-416 CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16356P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16356 [CRITICAL] CWE-416 CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16352P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16352 [CRITICAL] CWE-416 CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16377P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16377 [CRITICAL] CWE-693 CVE-2026-16377: Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2023-25152P3HIGHCVSS 8.8≥ 0, < 1:102.9.0+build1-0ubuntu0.18.04.1≥ 0, < 1:102.9.0+build1-0ubuntu0.20.04.1+1 more2023-03-27
CVE-2023-25152 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-25152, CVE-2023-28162,
CVE-2023-28176)
Lukas Bernhard discovered that Thunderbird did
osv
CVE-2025-2817P3HIGHCVSS 8.8fixed in 128.10.0≥ 129.0, < 138.02025-04-29
CVE-2025-2817 [HIGH] CWE-22 CVE-2025-2817: Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling
nvd
CVE-2025-0247P3CRITICALCVSS 9.8fixed in 134.02025-01-07
CVE-2025-0247 [CRITICAL] CWE-787 CVE-2025-0247: Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.
nvdosv
CVE-2025-6424P3CRITICALCVSS 9.8≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6424 [CRITICAL] CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
osv
CVE-2026-2778P3CRITICALCVSS 10.0fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2778 [CRITICAL] CWE-119 CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerab
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2023-29542P3CRITICALCVSS 9.8fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29542 [CRITICAL] CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that r
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerab
nvd
CVE-2026-16363P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16363 [CRITICAL] CWE-682 CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-2784P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2784 [CRITICAL] CWE-288 CVE-2026-2784: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firef
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-16350P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16350 [CRITICAL] CWE-119 CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in F
Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16357P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16357 [CRITICAL] CWE-119 CVE-2026-16357: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16355P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16355 [CRITICAL] CWE-843 CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla