Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 54 of 101
CVE-2026-8968P3HIGHCVSS 7.5fixed in 140.11fixed in 151.0.02026-05-19
CVE-2026-8968 [HIGH] CWE-400 CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerabilit
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2022-36320P3CRITICALCVSS 9.8≥ 0, < 1:102.2.2+build1-0ubuntu0.20.04.1≥ 0, < 1:102.2.2+build1-0ubuntu0.22.04.12022-07-27
CVE-2022-36320 [CRITICAL] CVE-2022-36320: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.
osv
CVE-2026-16376P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16376 [HIGH] CWE-400 CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-6773P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6773 [HIGH] CWE-190 CVE-2026-6773: Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was
Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6781P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6781 [HIGH] CWE-400 CVE-2026-6781: Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 15
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6780P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6780 [HIGH] CWE-400 CVE-2026-6780: Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 15
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-16409P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16409 [HIGH] CWE-824 CVE-2026-16409: Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thun
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2010-0174P3CRITICALCVSS 10.0≤ 3.0.3v0.1+59 more2010-04-05
CVE-2010-0174 [CRITICAL] CVE-2010-0174: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x b
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-0053P3CRITICALCVSS 10.0≤ 3.1.7v0.1+78 more2011-03-02
CVE-2011-0053 [CRITICAL] CVE-2011-0053: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-3651P3CRITICALCVSS 10.0v7.02011-11-09
CVE-2011-3651 [CRITICAL] CVE-2011-3651: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-2365P3CRITICALCVSS 10.0≤ 3.1.10v0.1+81 more2011-06-30
CVE-2011-2365 [CRITICAL] CVE-2011-2365: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbi
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2364.
nvd
CVE-2012-4218P3CRITICALCVSS 10.0fixed in 17.02012-11-21
CVE-2012-4218 [CRITICAL] CWE-416 CVE-2012-4218: Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla F
Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1681P3CRITICALCVSS 10.0≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1681 [CRITICAL] CWE-399 CVE-2013-1681: Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox
Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2025-3029P3HIGHCVSS 7.3fixed in 128.9.0≥ 129.0, < 137.02025-04-01
CVE-2025-3029 [HIGH] CWE-290 CVE-2025-3029: A crafted URL containing specific Unicode characters could have hidden the true origin of the page,
A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.
nvdosv
CVE-2012-4212P3CRITICALCVSS 10.0fixed in 17.02012-11-21
CVE-2012-4212 [CRITICAL] CWE-416 CVE-2012-4212: Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0,
Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1680P3CRITICALCVSS 10.0≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1680 [CRITICAL] CWE-119 CVE-2013-1680: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0,
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2011-0080P3CRITICALCVSS 10.0≤ 3.1.9v0.1+68 more2011-05-07
CVE-2011-0080 [CRITICAL] CVE-2011-0080: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-2364P3CRITICALCVSS 10.0≤ 3.1.10v0.1+81 more2011-06-30
CVE-2011-2364 [CRITICAL] CVE-2011-2364: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbi
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2365.
nvd
CVE-2013-1686P3CRITICALCVSS 10.0≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1686 [CRITICAL] CWE-399 CVE-2013-1686: Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firef
Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1682P3CRITICALCVSS 10.0≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1682 [CRITICAL] CVE-2013-1682: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd