cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 65 of 101
CVE-2015-4513P4HIGHCVSS 7.5≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-4513 [HIGH] CVE-2015-4513: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
osv
CVE-2008-5018P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.182008-11-13
CVE-2008-5018 [CRITICAL] CWE-399 CVE-2008-5018: The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
nvd
CVE-2026-0885P3MEDIUMCVSS 6.5fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0885 [MEDIUM] CWE-416 CVE-2026-0885: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2012-0459P4HIGHCVSS 7.5v5.0v6.0+7 more2012-03-14
CVE-2012-0459 [HIGH] CWE-264 CVE-2012-0459: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10. The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via dynamic modification of a keyframe
nvd
CVE-2011-3661P4HIGHCVSS 7.5v5.0v6.0+5 more2011-12-21
CVE-2011-3661 [HIGH] CWE-399 CVE-2011-3661: YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
nvd
CVE-2026-12302P3MEDIUMCVSS 6.5fixed in Thunderbird 140.12
CVE-2026-12302 [MEDIUM] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12302 Mozilla Foundation Security Advisory 2026-61 CVE: CVE-2026-12302 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.12
mozilla
CVE-2012-0462P4HIGHCVSS 7.5v5.0v6.0+7 more2012-03-14
CVE-2012-0462 [HIGH] CVE-2012-0462: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Fire Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vec
nvd
CVE-2025-14331P4MEDIUMCVSS 6.5fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14331 [MEDIUM] CWE-346 CVE-2025-14331: Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2006-1733P3MEDIUMCVSS 6.8≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1733 [MEDIUM] CWE-264 CVE-2006-1733: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inse
nvdosv
CVE-2015-7198P4HIGHCVSS 7.5≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-7198 [HIGH] CVE-2015-7198: Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42 Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted texture data.
osv
CVE-2015-2738P4CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2738 [CRITICAL] CWE-17 CVE-2015-2738: The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2015-2734P4CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2734 [CRITICAL] CWE-17 CVE-2015-2734: The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Fi The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2017-5449P4HIGHCVSS 7.5fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5449 [HIGH] CWE-20 CVE-2017-5449: A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2017-5467P4HIGHCVSS 7.5fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5467 [HIGH] CWE-119 CVE-2017-5467: A potential memory corruption and crash when using Skia content when drawing content outside of the A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2017-7755P4HIGHCVSS 7.8fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7755 [HIGH] CWE-426 CVE-2017-7755: The Firefox installer on Windows can be made to load malicious DLL files stored in the same director The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54
nvd
CVE-2008-2803P3MEDIUMCVSS 6.8≤ 2.0.0.14v2.0.0.0+11 more2008-07-07
CVE-2008-2803 [MEDIUM] CWE-264 CVE-2008-2803: The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0. The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving
nvd
CVE-2006-2787P4CRITICALCVSS 9.3v1.0v1.0.1+7 more2006-06-02
CVE-2006-2787 [CRITICAL] CVE-2006-2787: EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain priv EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.
nvdosv
CVE-2017-16541P3MEDIUMCVSS 6.5≥ 0, < 1:60.2.1-12017-11-04
CVE-2017-16541 [MEDIUM] CVE-2017-16541: Tor Browser before 7 Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
osv
CVE-2019-5798P4MEDIUMCVSS 6.5≥ 0, < 1:60.7.0-12019-05-23
CVE-2019-5798 [MEDIUM] CVE-2019-5798: Lack of correct bounds checking in Skia in Google Chrome prior to 73 Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
osv
CVE-2025-26696P4HIGHCVSS 7.0fixed in 128.8.0≥ 129.0, < 136.02025-03-10
CVE-2025-26696 [HIGH] CWE-290 CVE-2025-26696: Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which inst Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase