Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 66 of 101
CVE-2025-3028P4MEDIUMCVSS 6.5fixed in 128.9.0≥ 129.0, ≤ 137.02025-04-01
CVE-2025-3028 [MEDIUM] CWE-416 CVE-2025-3028: JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-aft
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.
nvdosv
CVE-2018-18506P4MEDIUMCVSS 5.9≥ 0, < 1:60.6.1-12019-02-05
CVE-2018-18506 [MEDIUM] CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file c
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually c
osv
CVE-2008-5017P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.182008-11-13
CVE-2008-5017 [CRITICAL] CWE-189 CVE-2008-5017: Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4,
Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.
nvd
CVE-2012-0463P4HIGHCVSS 7.5≥ 1.0, ≤ 3.1.19≤ 10.02012-03-14
CVE-2012-0463 [HIGH] CWE-20 CVE-2012-0463: The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 1
The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a d
nvd
CVE-2025-3932P4MEDIUMCVSS 6.5fixed in 128.10.1≥ 129.0, < 138.0.12025-05-14
CVE-2025-3932 [MEDIUM] CWE-288 CVE-2025-3932: It was possible to craft an email that showed a tracking link as an attachment. If the user attempte
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL head
nvdosv
CVE-2025-10532P4MEDIUMCVSS 6.5fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10532 [MEDIUM] CWE-754 CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firef
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-3031P4MEDIUMCVSS 6.5fixed in 137.02025-04-01
CVE-2025-3031 [MEDIUM] CWE-200 CVE-2025-3031: An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vul
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvdosv
CVE-2025-10529P4MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10529 [MEDIUM] CWE-942 CVE-2025-10529: Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Fire
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-4092P4MEDIUMCVSS 6.5fixed in 138.02025-04-29
CVE-2025-4092 [MEDIUM] CWE-119 CVE-2025-4092: Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvdosv
CVE-2025-4086P4MEDIUMCVSS 6.5fixed in 138.02025-04-29
CVE-2025-4086 [MEDIUM] CWE-451 CVE-2025-4086: A specially crafted filename containing a large number of encoded newline characters could obscure t
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.
*This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvd
CVE-2026-12309P4MEDIUMCVSS 6.5fixed in Thunderbird 152
CVE-2026-12309 [MEDIUM] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12309
Mozilla Foundation Security Advisory 2026-60
CVE: CVE-2026-12309
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152
mozilla
CVE-2026-6764P4MEDIUMCVSS 6.5≥ 140.0, < 140.10.02026-04-21
CVE-2026-6764 [MEDIUM] CWE-119 CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed
Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-8971P4MEDIUMCVSS 6.5fixed in 151.0.02026-05-19
CVE-2026-8971 [MEDIUM] CWE-346 CVE-2026-8971: Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2015-0797P4MEDIUMCVSS 6.8fixed in 31.7≥ 38.0, < 38.0.12015-05-14
CVE-2015-0797 [MEDIUM] CVE-2015-0797: GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Th
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
nvd
CVE-2026-6755P4MEDIUMCVSS 6.5fixed in 150.02026-04-21
CVE-2026-6755 [MEDIUM] CWE-352 CVE-2026-6755: Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2012-0461P4HIGHCVSS 7.5≥ 1.0, ≤ 3.1.19≤ 10.02012-03-14
CVE-2012-0461 [HIGH] CVE-2012-0461: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe
nvd
CVE-2015-7188P4HIGHCVSS 7.5≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-7188 [HIGH] CVE-2015-7188: Mozilla Firefox before 42
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.
osv
CVE-2015-2739P4CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2015-2737P4CRITICALCVSS 10.0≤ 38.0.12015-07-06
CVE-2015-2737 [CRITICAL] CWE-17 CVE-2015-2737: The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39
The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2006-5463P4HIGHCVSS 7.5v1.0v1.0.1+10 more2006-11-08
CVE-2006-5463 [HIGH] CVE-2006-5463: Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonk
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
nvd