cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 50 of 101
CVE-2026-4714P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4714 [HIGH] CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4713P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4713 [HIGH] CVE-2026-4713: Incorrect boundary conditions in the Graphics component Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4719P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4719 [HIGH] CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component Incorrect boundary conditions in the Graphics: Text component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4704P3HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4704 [HIGH] CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component Denial-of-service in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-8960P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8960 [HIGH] CWE-290 CVE-2026-8960: Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2025-3875P3HIGHCVSS 7.5fixed in 128.10.0≥ 129.0, < 138.0.12025-05-14
CVE-2025-3875 [HIGH] CWE-290 CVE-2025-3875: Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an in Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the actual address. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.
nvdosv
CVE-2026-6782P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6782 [HIGH] CWE-200 CVE-2026-6782: Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 a Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-16398P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16398 [HIGH] CWE-200 CVE-2026-16398: Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thun Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16399P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16399 [HIGH] CWE-346 CVE-2026-16399: Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2008-5014P3CRITICALCVSS 10.0≥ 2.0, < 2.0.0.182008-11-13
CVE-2008-5014 [CRITICAL] CWE-20 CVE-2008-5014: jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which trigg
nvd
CVE-2022-22759P3CRITICALCVSS 9.6fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22759 [CRITICAL] CWE-693 CVE-2022-22759: If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently append If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdosv
CVE-2025-1936P3HIGHCVSS 7.3fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1936 [HIGH] CWE-158 CVE-2025-1936: jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it wa jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerabilit
nvdosv
CVE-2014-1547P3CRITICALCVSS 10.0≤ 24.6v24.0+7 more2014-07-23
CVE-2014-1547 [CRITICAL] CVE-2014-1547: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2025-10528P3HIGHCVSS 7.3fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10528 [HIGH] CWE-693 CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2026-12318P3HIGHCVSS 7.3fixed in Thunderbird 152
CVE-2026-12318 [HIGH] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12318 Mozilla Foundation Security Advisory 2026-60 CVE: CVE-2026-12318 Product: Thunderbird Impact: high Fixed in: Thunderbird 152
mozilla
CVE-2011-2375P3CRITICALCVSS 10.0≤ 3.1.11v0.1+82 more2011-06-30
CVE-2011-2375 [CRITICAL] CVE-2011-2375: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunder Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-5125P3HIGHCVSS 8.8fixed in 52.7.0≥ unspecified, < 52.72018-06-11
CVE-2018-5125 [HIGH] CWE-119 CVE-2018-5125: Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evide Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvdosv
CVE-2013-1679P3CRITICALCVSS 10.0≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1679 [CRITICAL] CWE-399 CVE-2013-1679: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firef Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-5603P3CRITICALCVSS 10.0≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5603 [CRITICAL] CVE-2013-5603: Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in M Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
nvd
CVE-2009-2462P3CRITICALCVSS 10.0v2.0.0.0v2.0.0.1+19 more2009-07-22
CVE-2009-2462 [CRITICAL] CWE-399 CVE-2009-2462: The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame,
nvd
Mozilla Thunderbird vulnerabilities | cvebase