Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 58 of 101
CVE-2024-9399P3HIGHCVSS 7.5fixed in 128.3.0≥ 129.0, < 131.0+2 more2024-10-01
CVE-2024-9399 [HIGH] CWE-404 CVE-2024-9399: A website configured to initiate a specially crafted WebTransport session could crash the Firefox pr
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvdosv
CVE-2025-5262P3HIGHCVSS 7.5fixed in 128.11.0fixed in 139.0+2 more2025-05-27
CVE-2025-5262 [HIGH] CWE-415 CVE-2025-5262: A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initi
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
nvd
CVE-2011-3647P3CRITICALCVSS 9.3≤ 3.1.5v0.1+82 more2011-11-09
CVE-2011-3647 [CRITICAL] CVE-2011-3647: The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properl
The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.
nvd
CVE-2026-2801P3HIGHCVSS 7.5fixed in 148.02026-02-24
CVE-2026-2801 [HIGH] CWE-754 CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-12317P3HIGHCVSS 7.5fixed in Thunderbird 152
CVE-2026-12317 [HIGH] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12317
Mozilla Foundation Security Advisory 2026-60
CVE: CVE-2026-12317
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152
mozilla
CVE-2025-5270P3HIGHCVSS 7.5≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-05-27
CVE-2025-5270 [HIGH] CVE-2025-5270: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.
osv
CVE-2016-2836P3HIGHCVSS 8.8≥ 0, < 1:45.3.0+build1-0ubuntu0.14.04.4≥ 0, < 1:45.3.0+build1-0ubuntu0.16.04.22016-09-22
CVE-2016-2836 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, Carsten Book, Gary Kwong, Jesse Ruderman, Andrew
McCreight, and Phil Ringnalda discovered multiple memory safety issues in
Thunderbird. If a user were tricked in to opening a specially crafted
message, an attacker could potentially exploit these to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-2836)
osv
CVE-2016-1964P3HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1964 [HIGH] CVE-2016-1964: Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Fir
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
nvd
CVE-2024-9403P3HIGHCVSS 7.3fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9403 [HIGH] CWE-119 CVE-2024-9403: Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
nvdosv
CVE-2008-2799P3CRITICALCVSS 10.0≤ 2.0.0.14v2.0.0.0+11 more2008-07-07
CVE-2008-2799 [CRITICAL] CWE-399 CVE-2008-2799: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and ea
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.
nvd
CVE-2022-22753P3HIGHCVSS 7.1fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22753 [HIGH] CWE-367 CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6,
nvd
CVE-2010-0175P3CRITICALCVSS 9.3≤ 3.0.3v0.1+59 more2010-04-05
CVE-2010-0175 [CRITICAL] CWE-399 CVE-2010-0175: Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19
Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select ev
nvd
CVE-2011-0075P3CRITICALCVSS 10.0≤ 3.1.9v0.1+68 more2011-05-07
CVE-2011-0075 [CRITICAL] CVE-2011-0075: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0072P3CRITICALCVSS 10.0≤ 3.1.9v0.1+68 more2011-05-07
CVE-2011-0072 [CRITICAL] CVE-2011-0072: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0077P3CRITICALCVSS 10.0≤ 3.1.9v0.1+68 more2011-05-07
CVE-2011-0077 [CRITICAL] CVE-2011-0077: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0074P3CRITICALCVSS 10.0≤ 3.1.9v0.1+68 more2011-05-07
CVE-2011-0074 [CRITICAL] CVE-2011-0074: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0078P3CRITICALCVSS 10.0≤ 3.1.9v0.1+68 more2011-05-07
CVE-2011-0078 [CRITICAL] CVE-2011-0078: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2021-29951P3MEDIUMCVSS 6.5fixed in 78.10.1≥ unspecified, < 78.10.12021-06-24
CVE-2021-29951 [MEDIUM] CWE-269 CVE-2021-29951: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain net
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Not
nvd
CVE-2011-0081P3CRITICALCVSS 10.0v3.1.1v3.1.2+7 more2011-05-07
CVE-2011-0081 [CRITICAL] CVE-2011-0081: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x befor
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x before 4.0.1, and Thunderbird 3.1.x before 3.1.10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-0771P3CRITICALCVSS 10.0≤ 2.0.0.20v2.0.0.0+10 more2009-03-05
CVE-2009-0771 [CRITICAL] CWE-399 CVE-2009-0771: The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
nvd