cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 7 of 101
CVE-2026-2789P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2789 [CRITICAL] CWE-416 CVE-2026-2789: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Fir Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2786P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2786 [CRITICAL] CWE-416 CVE-2026-2786: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2782P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2782 [CRITICAL] CWE-269 CVE-2026-2782: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firef Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-16358P3CRITICALCVSS 9.8fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16358 [CRITICAL] CWE-346 CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1 Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16412P3UNKNOWNfixed in Thunderbird 153
CVE-2026-16412 Mozilla Foundation Security Advisory 2026-71: CVE-2026-16412 Mozilla Foundation Security Advisory 2026-71 CVE: CVE-2026-16412 Product: Thunderbird Impact: high Fixed in: Thunderbird 153
mozilla
CVE-2013-6671P3CRITICALCVSS 9.8fixed in 24.22013-12-11
CVE-2013-6671 [CRITICAL] CWE-94 CVE-2013-6671: The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24 The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.
nvd
CVE-2026-16359P3CRITICALCVSS 9.1fixed in 140.13.0≥ 141.0, < 153.02026-07-21
CVE-2026-16359 [CRITICAL] CWE-119 CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Fir Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-12315P3CRITICALCVSS 9.1fixed in Thunderbird 152
CVE-2026-12315 [CRITICAL] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12315 Mozilla Foundation Security Advisory 2026-60 CVE: CVE-2026-12315 Product: Thunderbird Impact: high Fixed in: Thunderbird 152
mozilla
CVE-2026-12304P3CRITICALCVSS 9.1fixed in Thunderbird 152
CVE-2026-12304 [CRITICAL] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12304 Mozilla Foundation Security Advisory 2026-60 CVE: CVE-2026-12304 Product: Thunderbird Impact: high Fixed in: Thunderbird 152
mozilla
CVE-2019-9794P3CRITICALCVSS 9.8fixed in 60.6.0≥ unspecified, < 60.62019-04-26
CVE-2019-9794 [CRITICAL] CWE-88 CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded duri A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third part
nvd
CVE-2026-2779P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2779 [CRITICAL] CWE-119 CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Fire Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2766P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2766 [CRITICAL] CWE-416 CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2765P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2765 [CRITICAL] CWE-416 CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-8094P3CRITICALCVSS 9.8fixed in 140.10.22026-05-07
CVE-2026-8094 [CRITICAL] CWE-94 CVE-2026-8094: Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunde Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
nvdmozilla
CVE-2026-0884P3CRITICALCVSS 9.8fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0884 [CRITICAL] CWE-416 CVE-2026-0884: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2026-2791P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2791 [CRITICAL] CWE-288 CVE-2026-2791: Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, F Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-5731P3CRITICALCVSS 9.8v140.9.0v149.0.12026-04-07
CVE-2026-5731 [CRITICAL] CWE-119 CVE-2026-5731: Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fi Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firef
nvd
CVE-2026-6768P3CRITICALCVSS 9.8fixed in 150.02026-04-21
CVE-2026-6768 [CRITICAL] CWE-288 CVE-2026-6768: Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-16407P3CRITICALCVSS 9.8fixed in 153.02026-07-21
CVE-2026-16407 [CRITICAL] CWE-284 CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-6760P3CRITICALCVSS 9.8fixed in 150.02026-04-21
CVE-2026-6760 [CRITICAL] CWE-288 CVE-2026-6760: Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
Mozilla Thunderbird vulnerabilities | cvebase