cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 57 of 101
CVE-2017-5464P3CRITICALCVSS 9.8fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5464 [CRITICAL] CWE-119 CVE-2017-5464: During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sy During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2014-1593P3MEDIUMCVSS 6.8≤ 31.22014-12-11
CVE-2014-1593 [MEDIUM] CWE-119 CVE-2014-1593: Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code via crafted media content.
nvdosv
CVE-2010-2770P3CRITICALCVSS 9.3≤ 3.0.6v0.1+68 more2010-09-09
CVE-2010-2770 [CRITICAL] CWE-119 CVE-2010-2770: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.
nvd
CVE-2010-3169P3CRITICALCVSS 9.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-3169 [CRITICAL] CVE-2010-3169: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6. Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0800P3MEDIUMCVSS 6.8fixed in 17.0.52013-04-03
CVE-2013-0800 [MEDIUM] CVE-2013-0800: Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values t
nvd
CVE-2012-3105P3CRITICALCVSS 9.3v5.0v6.0+14 more2012-06-05
CVE-2012-3105 [CRITICAL] CVE-2012-3105: The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox E The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruptio
nvd
CVE-2013-1684P3CRITICALCVSS 9.3≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1684 [CRITICAL] CWE-399 CVE-2013-1684: Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable funct Use-after-free vulnerability in the mozilla::dom::HTMLMediaElement::LookupMediaElementURITable function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted
nvd
CVE-2013-1685P3CRITICALCVSS 9.3≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1685 [CRITICAL] CWE-399 CVE-2013-1685: Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 2 Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site.
nvd
CVE-2017-5399P3CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5399 [CRITICAL] CWE-119 CVE-2017-5399: Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2018-5162P3HIGHCVSS 7.5fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5162 [HIGH] CWE-311 CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vu Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2011-3671P3HIGHCVSS 7.5v5.0v6.0+5 more2012-06-18
CVE-2011-3671 [HIGH] CWE-399 CVE-2011-3671: Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozil Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.
nvd
CVE-2025-8029P3HIGHCVSS 8.1fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8029 [HIGH] CWE-80 CVE-2025-8029: Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability w Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvdosv
CVE-2009-1833P3CRITICALCVSS 9.3≤ 2.0.0.19v0.1+65 more2009-06-12
CVE-2009-1833 [CRITICAL] CWE-94 CVE-2009-1833: The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey b The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c
nvd
CVE-2021-38498P3HIGHCVSS 7.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38498 [HIGH] CWE-416 CVE-2021-38498: During process shutdown, a document could have caused a use-after-free of a languages service object During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2023-5728P3HIGHCVSS 7.5fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5728 [HIGH] CWE-416 CVE-2023-5728: During garbage collection extra operations were performed on a object that should not be. This could During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2019-11755P3HIGHCVSS 7.5fixed in 68.1.1≥ unspecified, < 68.1.12019-09-27
CVE-2019-11755 [HIGH] CWE-347 CVE-2019-11755: A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was s A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a di
nvdosv
CVE-2026-6776P3HIGHCVSS 7.8fixed in 140.10.02026-04-21
CVE-2026-6776 [HIGH] CWE-119 CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in F Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2022-22737P3HIGHCVSS 7.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22737 [HIGH] CWE-362 CVE-2022-22737: Constructing audio sinks could have lead to a race condition when playing audio files and closing wi Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2025-3033P3HIGHCVSS 7.7fixed in 137.02025-04-01
CVE-2025-3033 [HIGH] CWE-73 CVE-2025-3033: After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file co After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvd
CVE-2024-7652P3HIGHCVSS 7.5fixed in 115.13.0≥ 116.0, < 128.0+2 more2024-09-06
CVE-2024-7652 [HIGH] CWE-476 CVE-2024-7652: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type co An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase