Mozilla Thunderbird vulnerabilities
1,818 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
1,818
CISA KEV
14
actively exploited
Public exploits
56
Exploited in wild
18
Severity breakdown
CRITICAL612HIGH551MEDIUM626LOW29
Vulnerabilities
Page 8 of 91
CVE-2025-11715HIGHCVSS 8.8fixed in 140.4.0fixed in 144.02025-10-14
CVE-2025-11715 [HIGH] CWE-119 CVE-2025-11715: Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunde
nvdosv
CVE-2025-11714HIGHCVSS 8.8fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11714 [HIGH] CWE-119 CVE-2025-11714: Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefo
nvdosv
CVE-2025-11711MEDIUMCVSS 6.5fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11711 [MEDIUM] CWE-591 CVE-2025-11711: There was a way to change the value of JavaScript Object properties that were supposed to be non-wri
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvdosv
CVE-2025-11712MEDIUMCVSS 6.1fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11712 [MEDIUM] CWE-116 CVE-2025-11712: A malicious page could have used the type attribute of an OBJECT tag to override the default browser
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunder
nvdosv
CVE-2025-11716MEDIUMCVSS 6.5fixed in 144.02025-10-14
CVE-2025-11716 [MEDIUM] CWE-284 CVE-2025-11716: Links in a sandboxed iframe could open an external app on Android without the required "allow-" perm
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
nvd
CVE-2025-10533HIGHCVSS 8.8fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10533 [HIGH] CWE-190 CVE-2025-10533: Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-10527HIGHCVSS 7.1fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10527 [HIGH] CWE-416 CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fix
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-10528HIGHCVSS 7.3fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10528 [HIGH] CWE-693 CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-10537HIGHCVSS 8.8fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10537 [HIGH] CWE-119 CVE-2025-10537: Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunde
nvdosv
CVE-2025-10534HIGHCVSS 8.1fixed in 143.02025-09-16
CVE-2025-10534 [HIGH] CWE-79 CVE-2025-10534: Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Th
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-10532MEDIUMCVSS 6.5fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10532 [MEDIUM] CWE-754 CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firef
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-10536MEDIUMCVSS 6.2fixed in 140.3.0≥ 141.0, < 143.02025-09-16
CVE-2025-10536 [MEDIUM] CWE-200 CVE-2025-10536: Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 1
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-10531MEDIUMCVSS 5.4fixed in 143.02025-09-16
CVE-2025-10531 [MEDIUM] CWE-288 CVE-2025-10531: Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firef
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-10529MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10529 [MEDIUM] CWE-942 CVE-2025-10529: Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Fire
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdosv
CVE-2025-10530MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10530 [MEDIUM] CWE-290 CVE-2025-10530: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-59375HIGHCVSS 7.5≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2025-09-15
CVE-2025-59375 [HIGH] CVE-2025-59375: libexpat in Expat before 2
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
osv
CVE-2025-9187CRITICALCVSS 9.8fixed in 142.02025-08-19
CVE-2025-9187 [CRITICAL] CWE-119 CVE-2025-9187: Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142 and Thunderbird 142.
nvd
CVE-2025-9179CRITICALCVSS 9.8fixed in 128.14.0fixed in 142.0+1 more2025-08-19
CVE-2025-9179 [CRITICAL] CWE-119 CVE-2025-9179: An attacker was able to perform memory corruption in the GMP process which processes encrypted media
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.1
nvdosv
CVE-2025-9185HIGHCVSS 8.1fixed in 128.14.0fixed in 142.0+1 more2025-08-19
CVE-2025-9185 [HIGH] CWE-119 CVE-2025-9185: Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefo
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed
nvdosv
CVE-2025-9182HIGHCVSS 7.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9182 [HIGH] CWE-400 CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was
Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.
nvdosv