Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 78 of 101
CVE-2016-9074P4MEDIUMCVSS 5.9fixed in 45.5.0≥ unspecified, < 45.52018-06-11
CVE-2016-9074 [MEDIUM] CWE-200 CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This is
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2020-16042P4MEDIUMCVSS 6.5≥ 0, < 1:78.6.0-12021-01-08
CVE-2020-16042 [MEDIUM] CVE-2020-16042: Uninitialized Use in V8 in Google Chrome prior to 87
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
osv
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in 115.5≥ unspecified, < 115.52023-11-21
CVE-2023-6205 [MEDIUM] CWE-416 CVE-2023-6205: It was possible to cause the use of a MessagePort after it had already been freed, which could poten
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvdosv
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22742 [MEDIUM] CWE-125 CVE-2022-22742: When inserting text while in edit mode, some characters might have lead to out-of-bounds memory acce
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2023-29535P4MEDIUMCVSS 6.5fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29535 [MEDIUM] CVE-2023-29535: Following a Garbage Collector compaction, weak maps may have been accessed before they were correctl
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvdosv
CVE-2024-0746P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0746 [MEDIUM] CWE-416 CVE-2024-0746: A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerabi
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2022-45403P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45403 [MEDIUM] CWE-203 CVE-2022-45403: Service Workers should not be able to infer information about opaque cross-origin responses; but tim
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2021-23998P4MEDIUMCVSS 6.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23998 [MEDIUM] CWE-345 CVE-2021-23998: Through complicated navigations with new windows, an HTTP page could have inherited a secure lock ic
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvdosv
CVE-2021-38497P4MEDIUMCVSS 6.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38497 [MEDIUM] CWE-346 CVE-2021-38497: Through use of reportValidity() and window.open(), a plain-text validation message could have been o
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2024-11706P4MEDIUMCVSS 6.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11706 [MEDIUM] CWE-476 CVE-2024-11706: A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `S
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvd
CVE-2021-4126P4MEDIUMCVSS 6.5fixed in 91.4.1≥ unspecified, < 91.4.12022-12-22
CVE-2021-4126 [MEDIUM] CVE-2021-4126: When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message l
When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression that the additional contents were also covered by the digital signature. Starting
nvdosv
CVE-2023-23601P4MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23601 [MEDIUM] CWE-346 CVE-2023-23601: Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab whic
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdosv
CVE-2025-11711P4MEDIUMCVSS 6.5fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11711 [MEDIUM] CWE-591 CVE-2025-11711: There was a way to change the value of JavaScript Object properties that were supposed to be non-wri
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvdosv
CVE-2026-12319P4MEDIUMCVSS 6.5fixed in 152.0.02026-06-16
CVE-2026-12319 [MEDIUM] CWE-400 CVE-2026-12319: Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 15
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2005-2261P4HIGHCVSS 7.5v0.1v0.2+15 more2005-07-13
CVE-2005-2261 [HIGH] CVE-2005-2261: Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0
Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.
nvd
CVE-2013-1717P4MEDIUMCVSS 5.4≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1717 [MEDIUM] CWE-264 CVE-2013-1717: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable path
nvd
CVE-2024-2609P4MEDIUMCVSS 6.1fixed in 115.10.0≥ unspecified, < 115.102024-03-19
CVE-2024-2609 [MEDIUM] CWE-356 CVE-2024-2609: The permission prompt input delay could expire while the window is not in focus. This makes it vulne
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2024-5693P4MEDIUMCVSS 6.1fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5693 [MEDIUM] CWE-829 CVE-2024-5693: Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image d
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvdosv
CVE-2011-3665P4HIGHCVSS 7.5v5.0v6.0+5 more2011-12-21
CVE-2011-3665 [HIGH] CWE-399 CVE-2011-3665: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling.
nvd
CVE-2023-4049P4MEDIUMCVSS 5.9≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4049 [MEDIUM] CVE-2023-4049: Race conditions in reference counting code were found through code inspection
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv