cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 55 of 101
CVE-2013-0801P3CRITICALCVSS 10.0≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-0801 [CRITICAL] CVE-2013-0801: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2006-5747P3HIGHCVSS 7.5v1.0v1.0.1+10 more2006-11-08
CVE-2006-5747 [HIGH] CVE-2006-5747: Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonk Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.
nvd
CVE-2026-16405P3UNKNOWNfixed in Thunderbird 140.13
CVE-2026-16405 Mozilla Foundation Security Advisory 2026-72: CVE-2026-16405 Mozilla Foundation Security Advisory 2026-72 CVE: CVE-2026-16405 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.13
mozilla
CVE-2016-10196P3HIGHCVSS 7.5fixed in 52.1.02017-03-15
CVE-2016-10196 [HIGH] CWE-787 CVE-2016-10196: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent befor Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
nvd
CVE-2014-1538P3CRITICALCVSS 10.0≤ 24.5v24.0+6 more2014-06-11
CVE-2014-1538 [CRITICAL] CVE-2014-1538: Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvdosv
CVE-2018-12364P3HIGHCVSS 8.8fixed in 52.9≥ 52.9.1, < 60.0+2 more2018-10-18
CVE-2018-12364 [HIGH] CWE-352 CVE-2018-12364: NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by mak NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR
nvdosv
CVE-2010-0159P3CRITICALCVSS 10.0fixed in 3.0.22010-02-22
CVE-2010-0159 [CRITICAL] CVE-2010-0159: The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cp
nvd
CVE-2013-0788P3CRITICALCVSS 10.0v17.0v17.0.1+3 more2013-04-03
CVE-2013-0788 [CRITICAL] CVE-2013-0788: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2011-2989P3CRITICALCVSS 10.0≤ 5.0v0.1+79 more2011-08-18
CVE-2011-2989 [CRITICAL] CWE-119 CVE-2011-2989: The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement WebGL, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2018-12371P3HIGHCVSS 8.8fixed in 60.0≥ unspecified, < 602020-07-09
CVE-2018-12371 [HIGH] CWE-190 CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.
nvdosv
CVE-2013-5591P3CRITICALCVSS 10.0≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5591 [CRITICAL] CVE-2013-5591: Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-0443P3CRITICALCVSS 10.0v5.0v6.0+5 more2012-02-01
CVE-2012-0443 [CRITICAL] CVE-2012-0443: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 9.0, Thund Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-4217P3CRITICALCVSS 9.3fixed in 17.02012-11-21
CVE-2012-4217 [CRITICAL] CWE-416 CVE-2012-4217: Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-4213P3CRITICALCVSS 9.3fixed in 17.02012-11-21
CVE-2012-4213 [CRITICAL] CWE-416 CVE-2012-4213: Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17 Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2009-0352P3CRITICALCVSS 10.0≤ 2.0.0.19v1.0+35 more2009-02-04
CVE-2009-0352 [CRITICAL] CWE-399 CVE-2009-0352: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.2 Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the
nvd
CVE-2019-9811P3HIGHCVSS 8.3fixed in 60.8≥ unspecified, < 60.82019-07-23
CVE-2019-9811 [HIGH] CWE-74 CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malic As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2014-1532P3CRITICALCVSS 9.8fixed in 24.52014-04-30
CVE-2014-1532 [CRITICAL] CWE-416 CVE-2014-1532: Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resol
nvdosv
CVE-2021-43535P3HIGHCVSS 8.8fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-43535 [HIGH] CWE-416 CVE-2021-43535: A use-after-free could have occured when an HTTP2 session object was released on a different thread, A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2013-0770P3CRITICALCVSS 9.3fixed in 17.0.22013-01-13
CVE-2013-0770 [CRITICAL] CVE-2013-0770: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbi Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-23954P3HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23954 [HIGH] CWE-843 CVE-2021-23954: Using the new logical assignment operators in a JavaScript switch statement could have caused a type Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase