Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 6 of 101
CVE-2026-16368P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16368 [CRITICAL] CWE-119 CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-6771P3CRITICALCVSS 9.8≥ 140.0, < 140.10.02026-04-21
CVE-2026-6771 [CRITICAL] CWE-288 CVE-2026-6771: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firef
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-16387P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16387 [CRITICAL] CWE-200 CVE-2026-16387: Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firef
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16390P3CRITICALCVSS 9.1fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16390 [CRITICAL] CWE-693 CVE-2026-16390: Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153,
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2025-4919P3HIGHCVSS 8.8fixed in 128.10.2≥ 138.0, < 138.0.22025-05-17
CVE-2025-4919 [HIGH] CWE-125 CVE-2025-4919: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing a
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
nvdosv
CVE-2010-3769P3CRITICALCVSS 9.3≤ 3.0.10v0.1+76 more2010-12-10
CVE-2010-3769 [CRITICAL] CWE-119 CVE-2010-3769: The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbi
The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.
nvd
CVE-2016-6354P3CRITICALCVSS 9.8≥ unspecified, < 52.12016-09-21
CVE-2016-6354 [CRITICAL] CWE-119 CVE-2016-6354: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow conte
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
nvd
CVE-2021-4140P3CRITICALCVSS 10.0fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2021-4140 [CRITICAL] CWE-91 CVE-2021-4140: It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. Th
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2012-4188P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-4188 [CRITICAL] CWE-119 CVE-2012-4188: Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 1
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4186P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-4186 [CRITICAL] CWE-119 CVE-2012-4186: Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 1
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2026-4689P3CRITICALCVSS 10.0fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4689 [CRITICAL] CWE-190 CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This v
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdosv
CVE-2020-6811P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6811 [HIGH] CWE-77 CVE-2020-6811: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Fire
nvdosv
CVE-2025-14321P3CRITICALCVSS 9.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14321 [CRITICAL] CWE-416 CVE-2025-14321: Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Fire
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2026-4701P3CRITICALCVSS 9.8≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4701 [CRITICAL] CVE-2026-4701: Use-after-free in the JavaScript Engine component
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4700P3CRITICALCVSS 9.8≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4700 [CRITICAL] CVE-2026-4700: Mitigation bypass in the Networking: HTTP component
Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-4717P3CRITICALCVSS 9.8≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4717 [CRITICAL] CVE-2026-4717: Privilege escalation in the Netmonitor component
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-16353P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16353 [CRITICAL] CWE-416 CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16382P3CRITICALCVSS 9.8fixed in 153.02026-07-21
CVE-2026-16382 [CRITICAL] CWE-693 CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16388P3CRITICALCVSS 9.8fixed in 153.02026-07-21
CVE-2026-16388 [CRITICAL] CWE-693 CVE-2026-16388: Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thu
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-2780P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2780 [CRITICAL] CWE-269 CVE-2026-2780: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv