cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 53 of 101
CVE-2025-8036P3HIGHCVSS 8.1fixed in 140.1.0fixed in 141.02025-07-22
CVE-2025-8036 [HIGH] CWE-350 CVE-2025-8036: Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CO Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvdosv
CVE-2025-8032P3HIGHCVSS 8.1fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8032 [HIGH] CWE-693 CVE-2025-8032: XSLT document loading did not correctly propagate the source document which bypassed its CSP. This v XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvdosv
CVE-2009-1832P3CRITICALCVSS 9.3≤ 2.0.0.19v0.1+65 more2009-06-12
CVE-2009-1832 [CRITICAL] CWE-94 CVE-2009-1832: Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction."
nvd
CVE-2013-1697P3CRITICALCVSS 9.3≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1697 [CRITICAL] CWE-264 CVE-2013-1697: The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thund The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that trigger
nvd
CVE-2023-5724P3HIGHCVSS 7.5fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5724 [HIGH] CWE-400 CVE-2023-5724: Drivers are not always robust to extremely large draw calls and in some cases this scenario could ha Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2019-11694P3HIGHCVSS 7.5fixed in 60.7.0≥ unspecified, < 60.72019-07-23
CVE-2019-11694 [HIGH] CWE-755 CVE-2019-11694: A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked t A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at that memory location. *Note: this issue only occurs on Windows. Other operating systems are unaffected.
nvd
CVE-2024-0743P3HIGHCVSS 7.5≥ unspecified, < 115.92024-01-23
CVE-2024-0743 [HIGH] CWE-252 CVE-2024-0743: An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. T An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
CVE-2020-12398P3HIGHCVSS 7.5fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12398 [HIGH] CWE-319 CVE-2020-12398: If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH resp If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.
nvdosv
CVE-2010-3777P3CRITICALCVSS 9.3v3.1v3.1.1+5 more2010-12-10
CVE-2010-3777 [CRITICAL] CWE-119 CVE-2010-3777: Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-29950P3HIGHCVSS 7.5fixed in 78.8.1≥ unspecified, < 78.8.12021-06-24
CVE-2021-29950 [HIGH] CWE-312 CVE-2021-29950: Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key impor Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
nvdosv
CVE-2011-2981P3CRITICALCVSS 9.3v3.0v3.0.1+22 more2011-08-18
CVE-2011-2981 [CRITICAL] CWE-16 CVE-2011-2981: The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
nvd
CVE-2023-4055P3HIGHCVSS 7.5≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4055 [HIGH] CVE-2023-4055: When the number of cookies per domain was exceeded in `document When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2024-1546P3HIGHCVSS 7.5fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1546 [HIGH] CWE-125 CVE-2024-1546: When storing and re-accessing data on a networking channel, the length of buffers may have been conf When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvdosv
CVE-2022-36319P3HIGHCVSS 7.5fixed in 102.1fixed in 91.12+2 more2022-12-22
CVE-2022-36319 [HIGH] CWE-1021 CVE-2022-36319: When combining CSS properties for overflow and transform, the mouse cursor could interact with diffe When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
nvdosv
CVE-2023-4583P3HIGHCVSS 7.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4583 [HIGH] CWE-754 CVE-2023-4583: When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvdosv
CVE-2024-10458P3HIGHCVSS 7.5fixed in 128.4.0≥ 129.0, < 132.0+2 more2024-10-29
CVE-2024-10458 [HIGH] CWE-281 CVE-2024-10458: A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `objec A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2024-11702P3HIGHCVSS 7.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11702 [HIGH] CWE-838 CVE-2024-11702: Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have ina Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvd
CVE-2026-0889P3HIGHCVSS 7.5fixed in 147.02026-01-13
CVE-2026-0889 [HIGH] CWE-400 CVE-2026-0889: Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2026-4727P3HIGHCVSS 7.5fixed in 149.02026-03-24
CVE-2026-4727 [HIGH] CWE-400 CVE-2026-4727: Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2025-1931P3HIGHCVSS 7.5fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1931 [HIGH] CWE-416 CVE-2025-1931: It was possible to cause a use-after-free in the content process side of a WebTransport connection, It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase