cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 70 of 101
CVE-2022-45405P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45405 [MEDIUM] CWE-416 CVE-2022-45405: Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led t Freeing arbitrary nsIInputStream's on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2022-46875P4MEDIUMCVSS 6.5fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46875 [MEDIUM] CWE-287 CVE-2022-46875: The executable file warning was not presented when downloading .atloc and .ftploc files, which can r The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2023-25752P4MEDIUMCVSS 6.5fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-25752 [MEDIUM] CVE-2023-25752: When accessing throttled streams, the count of available bytes needed to be checked in the calling f When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvdosv
CVE-2022-31744P4MEDIUMCVSS 6.5fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-31744 [MEDIUM] CWE-79 CVE-2022-31744: An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource: An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
nvdosv
CVE-2022-45420P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45420 [MEDIUM] CWE-1021 CVE-2022-45420: Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2024-10462P4MEDIUMCVSS 6.5fixed in 128.4.0≥ 129.0, < 132.0+2 more2024-10-29
CVE-2024-10462 [MEDIUM] CWE-290 CVE-2024-10462: Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerabili Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2024-10465P4MEDIUMCVSS 6.5fixed in 128.4.0≥ 129.0, < 132.0+2 more2024-10-29
CVE-2024-10465 [MEDIUM] CWE-290 CVE-2024-10465: A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerabi A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2024-7529P4MEDIUMCVSS 6.5fixed in 115.14.0v128.0.1+2 more2024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdosv
CVE-2025-5986P4MEDIUMCVSS 6.5fixed in 128.11.1≥ 135.0, < 139.0.22025-06-11
CVE-2025-5986 [MEDIUM] CWE-451 CVE-2025-5986: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf fi A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email
nvdosv
CVE-2019-7317P4MEDIUMCVSS 5.3≥ 0, < 1:60.7.0-12019-02-04
CVE-2019-7317 [MEDIUM] CVE-2019-7317: png_image_free in png png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
osv
CVE-2024-11708P4MEDIUMCVSS 6.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11708 [MEDIUM] CWE-362 CVE-2024-11708: Missing thread synchronization primitives could have led to a data race on members of the PlaybackPa Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvd
CVE-2025-1013P4MEDIUMCVSS 6.5fixed in 128.7.0≥ 129.0, < 135.02025-02-04
CVE-2025-1013 [MEDIUM] CWE-362 CVE-2025-1013: A race condition could have led to private browsing tabs being opened in normal browsing windows. Th A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-6429P4MEDIUMCVSS 6.5≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6429 [MEDIUM] CVE-2025-6429: Firefox could have incorrectly parsed a URL and rewritten it to the youtube Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
osv
CVE-2025-10530P4MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10530 [MEDIUM] CWE-290 CVE-2025-10530: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-5271P4MEDIUMCVSS 6.5≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-05-27
CVE-2025-5271 [MEDIUM] CVE-2025-5271: Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139 and Thunderbird < 139.
osv
CVE-2026-8388P4MEDIUMCVSS 6.5fixed in Thunderbird 140.11
CVE-2026-8388 [MEDIUM] Mozilla Foundation Security Advisory 2026-51: CVE-2026-8388 Mozilla Foundation Security Advisory 2026-51 CVE: CVE-2026-8388 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.11
mozilla
CVE-2015-4489P4HIGHCVSS 7.5≥ 0, < 1:38.2.0+build1-0ubuntu0.14.04.12015-08-11
CVE-2015-4489 [HIGH] CVE-2015-4489: The nsTArray_Impl class in Mozilla Firefox before 40 The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
osv
CVE-2025-3523P4MEDIUMCVSS 6.4fixed in 128.9.2≥ 129.0, < 137.0.22025-04-15
CVE-2025-3523 [MEDIUM] CWE-451 CVE-2025-3523: When an email contains multiple attachments with external links via the X-Mozilla-External-Attachmen When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunder
nvdosv
CVE-2015-4517P4HIGHCVSS 7.5≥ 0, < 1:38.3.0+build1-0ubuntu0.14.04.12015-09-22
CVE-2015-4517 [HIGH] CVE-2015-4517: NetworkUtils NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
osv
CVE-2008-5500P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.192008-12-17
CVE-2008-5500 [CRITICAL] CWE-399 CVE-2008-5500: The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x befor The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.
nvd
Mozilla Thunderbird vulnerabilities | cvebase