cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 80 of 101
CVE-2023-25742P4MEDIUMCVSS 6.5fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25742 [MEDIUM] CVE-2023-25742: When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing th When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2022-22747P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22747 [MEDIUM] CWE-295 CVE-2022-22747: After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificat After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2025-1934P4MEDIUMCVSS 6.5fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1934 [MEDIUM] CVE-2025-1934: It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, poten It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2022-38475P4MEDIUMCVSS 6.5≥ 0, < 1:102.2.2+build1-0ubuntu0.20.04.1≥ 0, < 1:102.2.2+build1-0ubuntu0.22.04.12022-08-24
CVE-2022-38475 [MEDIUM] CVE-2022-38475: An attacker could have written a value to the first element in a zero-length JavaScript array An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.
osv
CVE-2020-26958P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26958 [MEDIUM] CWE-79 CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercept Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdosv
CVE-2020-26978P4MEDIUMCVSS 6.1fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26978 [MEDIUM] CVE-2020-26978: Using techniques that built on the slipstream research, a malicious webpage could have exposed both Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdosv
CVE-2025-0510P4MEDIUMCVSS 6.5≥ 128.0.1, < 128.7.0≥ 131.0, < 135.02025-02-04
CVE-2025-0510 [MEDIUM] CVE-2025-0510: Thunderbird displayed an incorrect sender address if the From field of an email used the invalid gro Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
nvdosv
CVE-2024-1551P4MEDIUMCVSS 6.1fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1551 [MEDIUM] CWE-565 CVE-2024-1551: Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attack Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, an
nvdosv
CVE-2024-1550P4MEDIUMCVSS 6.1fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1550 [MEDIUM] CWE-1021 CVE-2024-1550: A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 1
nvdosv
CVE-2024-4769P4MEDIUMCVSS 5.9fixed in 115.11.0≥ unspecified, < 115.112024-05-14
CVE-2024-4769 [MEDIUM] CWE-351 CVE-2024-4769: When importing resources using Web Workers, error messages would distinguish the difference between When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvdosv
CVE-2017-7829P4MEDIUMCVSS 5.3fixed in 52.5.2≥ unspecified, < 52.5.22018-06-11
CVE-2017-7829 [MEDIUM] CWE-20 CVE-2017-7829: It is possible to spoof the sender's email address and display an arbitrary sender address to the em It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
nvdosv
CVE-2025-0238P4MEDIUMCVSS 5.3fixed in 128.6≥ 129.0, < 134.02025-01-07
CVE-2025-0238 [MEDIUM] CWE-416 CVE-2025-0238: Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, lead Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Firefox ESR 115.19, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2025-5283P4MEDIUMCVSS 5.4≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5283 [MEDIUM] CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137 Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
osv
CVE-2026-2804P4MEDIUMCVSS 5.4fixed in 148.02026-02-24
CVE-2026-2804 [MEDIUM] CWE-416 CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-0886P4MEDIUMCVSS 5.3fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0886 [MEDIUM] CWE-119 CVE-2026-0886: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147 Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2026-0883P4MEDIUMCVSS 5.3fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0883 [MEDIUM] CWE-200 CVE-2026-0883: Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Fir Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2024-10460P4MEDIUMCVSS 5.3fixed in 128.4≥ 129, < 132+2 more2024-10-29
CVE-2024-10460 [MEDIUM] CWE-346 CVE-2024-10460: The origin of an external protocol handler prompt could have been obscured using a data: URL within The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2026-12329P4MEDIUMCVSS 5.3≥ 140.0, < 140.12.02026-06-16
CVE-2026-12329 [MEDIUM] CWE-119 CVE-2026-12329: Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.1 Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
nvdmozilla
CVE-2026-0888P4MEDIUMCVSS 5.3fixed in 147.02026-01-13
CVE-2026-0888 [MEDIUM] CWE-200 CVE-2026-0888: Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunder Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2026-12307P4MEDIUMCVSS 5.3fixed in Thunderbird 152
CVE-2026-12307 [MEDIUM] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12307 Mozilla Foundation Security Advisory 2026-60 CVE: CVE-2026-12307 Product: Thunderbird Impact: high Fixed in: Thunderbird 152
mozilla
Mozilla Thunderbird vulnerabilities | cvebase