cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 63 of 101
CVE-2008-4068P4HIGHCVSS 7.8fixed in 2.0.0.172008-09-24
CVE-2008-4068 [HIGH] CWE-22 CVE-2008-4068: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbi Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a re
nvd
CVE-2015-2708P4HIGHCVSS 7.5≤ 31.52015-05-14
CVE-2015-2708 [HIGH] CVE-2015-2708: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-4500P4HIGHCVSS 7.5≥ 0, < 1:38.3.0+build1-0ubuntu0.14.04.12015-10-05
CVE-2015-4500 [HIGH] thunderbird vulnerabilities thunderbird vulnerabilities Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David Major, Andrew McCreight, and Cameron McCormack discovered multiple memory safety issues in Thunderbird. If a user were tricked in to opening a specially crafted message, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Thunderbird. (CVE-
osv
CVE-2010-1201P4CRITICALCVSS 9.3≤ 3.0.4v0.1+40 more2010-06-24
CVE-2010-1201 [CRITICAL] CVE-2010-1201: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-0815P4HIGHCVSS 7.5≤ 31.52015-04-01
CVE-2015-0815 [HIGH] CVE-2015-0815: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-0836P4HIGHCVSS 7.5≤ 31.4v31.0+3 more2015-02-25
CVE-2015-0836 [HIGH] CVE-2015-0836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2023-23599P3MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23599 [MEDIUM] CWE-116 CVE-2023-23599: When copying a network request from the developer tools panel as a curl command the output was not b When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdosv
CVE-2014-1574P4HIGHCVSS 7.5v31.0v31.1.02014-10-15
CVE-2014-1574 [HIGH] CVE-2014-1574: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2014-8634P4HIGHCVSS 7.5≤ 31.3.02015-01-14
CVE-2014-8634 [HIGH] CVE-2014-8634: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2025-1938P3MEDIUMCVSS 6.5fixed in 128.7.0≥ 129.0, < 135.02025-03-04
CVE-2025-1938 [MEDIUM] CWE-787 CVE-2025-1938: Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderb
nvdosv
CVE-2016-1526P4HIGHCVSS 8.1≤ 38.5.12016-02-13
CVE-2016-1526 [HIGH] CWE-119 CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozill The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smar
nvd
CVE-2026-6763P3MEDIUMCVSS 6.5≥ 140.0, < 140.10.02026-04-21
CVE-2026-6763 [MEDIUM] CWE-693 CVE-2026-6763: Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firef Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2025-4088P3MEDIUMCVSS 6.5fixed in 138.02025-04-29
CVE-2025-4088 [MEDIUM] CWE-352 CVE-2025-4088: A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentiale A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvdosv
CVE-2015-7205P4CRITICALCVSS 10.0≥ 0, < 1:38.5.1+build2-0ubuntu0.14.04.12015-12-15
CVE-2015-7205 [CRITICAL] CVE-2015-7205: Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43 Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.
osv
CVE-2011-3652P4CRITICALCVSS 10.0≤ 7.0.1v0.1+97 more2011-11-09
CVE-2011-3652 [CRITICAL] CWE-119 CVE-2011-3652: The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly alloca The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2007-2868P3CRITICALCVSS 9.3v1.5v1.5.0.1+13 more2007-06-01
CVE-2007-2868 [CRITICAL] CWE-94 CVE-2007-2868: Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger memory corruption.
nvd
CVE-2016-9897P3HIGHCVSS 7.5fixed in 45.6.0≥ unspecified, < 45.62018-06-11
CVE-2016-9897 [HIGH] CWE-119 CVE-2016-9897: Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2005-0399P3MEDIUMCVSS 5.1v0.1v0.2+12 more2005-05-02
CVE-2005-0399 [MEDIUM] CVE-2005-0399: Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunder Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.
nvd
CVE-2012-0452P4HIGHCVSS 7.5v10.02012-02-11
CVE-2012-0452 [HIGH] CWE-399 CVE-2012-0452: Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's ac
nvd
CVE-2010-0173P3CRITICALCVSS 9.3≤ 3.0.3v0.1+59 more2010-04-05
CVE-2010-0173 [CRITICAL] CVE-2010-0173: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
Mozilla Thunderbird vulnerabilities | cvebase