Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 69 of 101
CVE-2021-23991P4MEDIUMCVSS 6.8fixed in 78.9.1≥ unspecified, < 78.9.12021-06-24
CVE-2021-23991 [MEDIUM] CVE-2021-23991: If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validi
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send
nvdosv
CVE-2025-10527P4HIGHCVSS 7.1fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10527 [HIGH] CWE-416 CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fix
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2024-5700P4HIGHCVSS 7.0fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5700 [HIGH] CWE-786 CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvdosv
CVE-2006-0294P4HIGHCVSS 7.5v1.52006-02-02
CVE-2006-0294 [HIGH] CVE-2006-0294: Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
nvdosv
CVE-2006-2775P4HIGHCVSS 7.5≤ 1.5.0.1v0.1+20 more2006-06-02
CVE-2006-2775 [HIGH] CWE-264 CVE-2006-2775: Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under ce
Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wrong URL.
nvdosv
CVE-2021-38505P4MEDIUMCVSS 6.5fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38505 [MEDIUM] CWE-668 CVE-2021-38505: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will re
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before v
nvd
CVE-2023-5169P4MEDIUMCVSS 6.5fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5169 [MEDIUM] CWE-787 CVE-2023-5169: A compromised content process could have provided malicious data in a `PathRecording` resulting in a
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvdosv
CVE-2023-5732P4MEDIUMCVSS 6.5fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5732 [MEDIUM] CVE-2023-5732: An attacker could have created a malicious link using bidirectional characters to spoof the location
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2023-5727P4MEDIUMCVSS 6.5fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5727 [MEDIUM] CVE-2023-5727: The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxb
The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer.
*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2023-4053P4MEDIUMCVSS 6.5≥ unspecified, < 115.22023-08-01
CVE-2023-4053 [MEDIUM] CWE-59 CVE-2023-4053: A website could have obscured the full screen notification by using a URL with a scheme handled by a
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvdosv
CVE-2022-45410P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45410 [MEDIUM] CWE-862 CVE-2022-45410: When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request w
When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2021-23982P4MEDIUMCVSS 6.5fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23982 [MEDIUM] CWE-326 CVE-2021-23982: Using techniques that built on the slipstream research, a malicious webpage could have scanned both
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvdosv
CVE-2024-0753P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0753 [MEDIUM] CVE-2024-0753: In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerabil
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2022-45408P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45408 [MEDIUM] CWE-79 CVE-2022-45408: Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen wi
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2022-26386P4MEDIUMCVSS 6.5fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26386 [MEDIUM] CWE-377 CVE-2022-26386: Previously Firefox for macOS and Linux would download temporary files to a user-specific directory i
Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in /tmp, but this behavior was changed to download them to /tmp where they could be affected by other local users. This behavior was reverted to the original, user-specific directory. *This bug only affects Firefox for macOS and Linux. Other operating
nvdosv
CVE-2024-1547P4MEDIUMCVSS 6.5fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1547 [MEDIUM] CWE-290 CVE-2024-1547: Through a series of API calls and redirects, an attacker-controlled alert dialog could have been dis
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvdosv
CVE-2022-3032P4MEDIUMCVSS 6.5fixed in 91.13.1≥ 102.0, < 102.2.1+2 more2022-12-22
CVE-2022-3032 [MEDIUM] CWE-610 CVE-2022-3032: When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdo
When receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Th
nvdosv
CVE-2023-4574P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4574 [MEDIUM] CWE-416 CVE-2023-4574: When creating a callback over IPC for showing the Color Picker window, multiple of the same callback
When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox
nvdosv
CVE-2023-4575P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4575 [MEDIUM] CWE-416 CVE-2023-4575: When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox E
nvdosv
CVE-2023-23598P4MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23598 [MEDIUM] CVE-2023-23598: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plai
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdosv