Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 60 of 101
CVE-2017-7803P3HIGHCVSS 7.5fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7803 [HIGH] CWE-269 CVE-2017-7803: When a page's content security policy (CSP) header contains a "sandbox" directive, other directives
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2018-5184P3HIGHCVSS 7.5fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5184 [HIGH] CWE-326 CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerabili
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2017-5411P3HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5411 [HIGH] CWE-416 CVE-2017-5411: A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulne
nvd
CVE-2025-8039P3HIGHCVSS 8.1fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8039 [HIGH] CWE-200 CVE-2025-8039: In some cases search terms persisted in the URL bar even after navigating away from the search page.
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvdosv
CVE-2014-1594P3MEDIUMCVSS 6.8≤ 31.22014-12-11
CVE-2014-1594 [MEDIUM] CWE-20 CVE-2014-1594: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey be
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLayer data type to the BasicContainerLayer data type.
nvdosv
CVE-2012-3991P3CRITICALCVSS 9.3fixed in 16.02012-10-10
CVE-2012-3991 [CRITICAL] CWE-264 CVE-2012-3991: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.
nvd
CVE-2017-7765P3HIGHCVSS 7.5fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7765 [HIGH] CWE-20 CVE-2017-7765: The "Mark of the Web" was not correctly saved on Windows when files with very long names were downlo
The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is not shown. Note: This attack only affects Windows operating systems. Other operating systems are
nvd
CVE-2015-7189P3MEDIUMCVSS 6.8≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-7189 [MEDIUM] CVE-2015-7189: Race condition in the JPEGEncoder function in Mozilla Firefox before 42
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
osv
CVE-2021-23961P3HIGHCVSS 7.4≥ 0, < 1:78.11.0+build1-0ubuntu0.20.04.22021-06-22
CVE-2021-23961 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, spoof the UI, bypass security restrictions,
or execute arbitrary code. (CVE-2021-23961, CVE-2021-23981,
CVE-2021-23982, CVE-2021-23987, CVE-2021-23994, CVE-2021-23998,
CVE-2
osv
CVE-2023-37208P3HIGHCVSS 7.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37208 [HIGH] CWE-434 CVE-2023-37208: When opening Diagcab files, Firefox did not warn the user that these files may contain malicious cod
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvdosv
CVE-2023-1999P3HIGHCVSS 7.5≥ 0, < 1:102.10.0-1~deb11u1≥ 0, < 1:102.10.0-12023-06-20
CVE-2023-1999 [HIGH] CVE-2023-1999: There exists a use after free/double free in libwebp
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
osv
CVE-2023-32214P3HIGHCVSS 7.5fixed in 102.11≥ unspecified, < 102.112023-06-19
CVE-2023-32214 [HIGH] CVE-2023-32214: Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of servic
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service.
*Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2013-0773P3CRITICALCVSS 9.3fixed in 17.0.32013-02-19
CVE-2013-0773 [CRITICAL] CVE-2013-0773: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox bef
The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects o
nvd
CVE-2006-6500P3MEDIUMCVSS 6.8fixed in 1.5.0.92006-12-20
CVE-2006-6500 [MEDIUM] CWE-119 CVE-2006-6500: Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows
nvd
CVE-2025-9182P3HIGHCVSS 7.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9182 [HIGH] CWE-400 CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was
Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.
nvdosv
CVE-2016-1952P3HIGHCVSS 8.8≤ 38.6.02016-03-13
CVE-2016-1952 [HIGH] CWE-119 CVE-2016-1952: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2014-1497P3HIGHCVSS 8.8fixed in 24.42014-03-19
CVE-2014-1497 [HIGH] CWE-125 CVE-2014-1497: The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x b
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impac
nvd
CVE-2006-2780P3CRITICALCVSS 9.3≤ 1.5.0.32006-06-02
CVE-2006-2780 [CRITICAL] CWE-94 CVE-2006-2780: Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause
Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.
nvdosv
CVE-2004-0757P4CRITICALCVSS 10.0≤ 0.72004-08-18
CVE-2004-0757 [CRITICAL] CVE-2004-0757: Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox be
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.
nvd
CVE-2006-1790P3CRITICALCVSS 10.0≥ 0, < 1.5.0.2-12006-04-14
CVE-2006-1790 [CRITICAL] CVE-2006-1790: A regression fix in Mozilla Firefox 1
A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.
osv