cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 71 of 101
CVE-2024-6600P4MEDIUMCVSS 6.3fixed in 115.13≥ 116.0, < 128.0+2 more2024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosv
CVE-2025-2830P4MEDIUMCVSS 6.3fixed in 128.9.2≥ 129.0, < 137.0.22025-04-15
CVE-2025-2830 [MEDIUM] CWE-22 CVE-2025-2830: By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Th By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux
nvdosv
CVE-2006-1737P4CRITICALCVSS 9.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1737 [CRITICAL] CWE-189 CVE-2006-1737: Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.
nvdosv
CVE-2021-29969P4MEDIUMCVSS 5.9fixed in 78.12≥ unspecified, < 78.122021-08-05
CVE-2021-29969 [MEDIUM] CWE-552 CVE-2021-29969: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show
nvdosv
CVE-2020-15646P4MEDIUMCVSS 5.9fixed in 68.10.0≥ unspecified, < 68.10.02020-10-08
CVE-2020-15646 [MEDIUM] CVE-2020-15646: If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
nvdosv
CVE-2024-2605P4MEDIUMCVSS 5.9fixed in 115.9.0≥ unspecified, < 115.92024-03-19
CVE-2024-2605 [MEDIUM] CVE-2024-2605: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system esca An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2025-4084P4MEDIUMCVSS 5.7fixed in 128.10.02025-04-29
CVE-2025-4084 [MEDIUM] CWE-116 CVE-2025-4084: Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker co Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox ESR 128.10, Firef
nvd
CVE-2009-2408P4MEDIUMCVSS 5.9fixed in 2.0.0.232009-07-30
CVE-2009-2408 [MEDIUM] CWE-295 CVE-2009-2408: Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificat
nvd
CVE-2011-3079P4CRITICALCVSS 10.0≤ 31.6≤ 38.0+1 more2012-05-01
CVE-2011-3079 [CRITICAL] CWE-399 CVE-2011-3079: The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
nvd
CVE-2013-5596P4MEDIUMCVSS 6.8≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5596 [MEDIUM] CWE-119 CVE-2013-5596: The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24. The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attackers to execute arbitrary code or cause a denial of service (race condition and application crash) via
nvd
CVE-2011-3650P4CRITICALCVSS 9.3≤ 3.1.5v0.1+87 more2011-11-09
CVE-2011-3650 [CRITICAL] CWE-119 CVE-2011-3650: Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 d Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is
nvd
CVE-2019-20503P4MEDIUMCVSS 6.5≥ 0, < 1:68.6.0-12020-03-06
CVE-2019-20503 [MEDIUM] CVE-2019-20503: usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
osv
CVE-2020-12418P4MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12418 [MEDIUM] CWE-125 CVE-2020-12418: Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking proce Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2015-4520P4MEDIUMCVSS 6.4≥ 0, < 1:38.3.0+build1-0ubuntu0.14.04.12015-09-22
CVE-2015-4520 [MEDIUM] CVE-2015-4520: Mozilla Firefox before 41 Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.
osv
CVE-2017-5407P4MEDIUMCVSS 6.5fixed in 45.8.0fixed in 52.0+2 more2018-06-11
CVE-2017-5407 [MEDIUM] CWE-200 CVE-2017-5407: Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Fire
nvd
CVE-2010-1215P4MEDIUMCVSS 6.8v3.12010-07-30
CVE-2010-1215 [MEDIUM] CWE-94 CVE-2010-1215: Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement acce Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."
nvd
CVE-2022-28282P4MEDIUMCVSS 6.5fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28282 [MEDIUM] CWE-416 CVE-2022-28282: By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by d By using a link with rel="localization" a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvdosv
CVE-2020-12421P4MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.10.02020-07-09
CVE-2020-12421 [MEDIUM] CWE-295 CVE-2020-12421: When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected ( When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvdosv
CVE-2021-43542P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43542 [MEDIUM] CWE-209 CVE-2021-43542: Using XMLHttpRequest, an attacker could have identified installed applications by probing error mess Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
CVE-2021-43541P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43541 [MEDIUM] CVE-2021-43541: When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces w When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase