cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 81 of 101
CVE-2026-12306P4MEDIUMCVSS 5.3fixed in Thunderbird 140.12
CVE-2026-12306 [MEDIUM] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12306 Mozilla Foundation Security Advisory 2026-61 CVE: CVE-2026-12306 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.12
mozilla
CVE-2026-12308P4MEDIUMCVSS 5.3fixed in Thunderbird 140.12
CVE-2026-12308 [MEDIUM] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12308 Mozilla Foundation Security Advisory 2026-61 CVE: CVE-2026-12308 Product: Thunderbird Impact: high Fixed in: Thunderbird 140.12
mozilla
CVE-2026-6767P4MEDIUMCVSS 5.3≥ 140.0, < 140.10.02026-04-21
CVE-2026-6767 [MEDIUM] CWE-119 CVE-2026-6767: Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6765P4MEDIUMCVSS 5.3fixed in 140.10.02026-04-21
CVE-2026-6765 [MEDIUM] CWE-359 CVE-2026-6765: Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2011-2980P4HIGHCVSS 7.2v3.0v3.0.1+22 more2011-08-18
CVE-2011-2980 [HIGH] CVE-2011-2980: Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox befor Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
nvd
CVE-2015-0807P4MEDIUMCVSS 6.8≤ 31.52015-04-01
CVE-2015-0807 [MEDIUM] CVE-2015-0807: The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted w
nvdosv
CVE-2011-3666P4MEDIUMCVSS 6.8≤ 3.1.16v0.1+91 more2011-12-21
CVE-2011-3666 [MEDIUM] CVE-2011-3666: Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files t Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
nvd
CVE-2021-23973P4MEDIUMCVSS 6.5fixed in 78.82021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvdosv
CVE-2020-6795P4MEDIUMCVSS 6.5fixed in 68.5.0≥ unspecified, < 68.52020-03-02
CVE-2020-6795 [MEDIUM] CWE-476 CVE-2020-6795: When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing cod When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploitable crash. This vulnerability affects Thunderbird < 68.5.
nvdosv
CVE-2020-15648P4MEDIUMCVSS 6.5fixed in 78.0≥ unspecified, < 782020-08-10
CVE-2020-15648 [MEDIUM] CWE-1021 CVE-2020-15648: Using object or embed tags, it was possible to frame other websites, even if they disallowed framing Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
nvdosv
CVE-2020-6798P4MEDIUMCVSS 6.1fixed in 68.5.0≥ unspecified, < 68.52020-03-02
CVE-2020-6798 [MEDIUM] CWE-79 CVE-2020-6798: If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsin If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because
nvdosv
CVE-2019-11739P4MEDIUMCVSS 6.5fixed in 60.9.0≥ 68.0, < 68.1.0+2 more2019-09-27
CVE-2019-11739 [MEDIUM] CWE-319 CVE-2019-11739: Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included i Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.
nvdosv
CVE-2022-42929P4MEDIUMCVSS 6.5fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42929 [MEDIUM] CWE-400 CVE-2022-42929: If a website called `window.print()` in a particular way, it could cause a denial of service of the If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosv
CVE-2020-15677P4MEDIUMCVSS 6.1fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15677 [MEDIUM] CWE-601 CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site d By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvdosv
CVE-2023-4578P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4578 [MEDIUM] CWE-770 CVE-2023-4578: When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling ` When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117,
nvdosv
CVE-2020-15676P4MEDIUMCVSS 6.1fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15676 [MEDIUM] CWE-79 CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvdosv
CVE-2020-26951P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26951 [MEDIUM] CWE-79 CVE-2020-26951: A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, e A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbi
nvdosv
CVE-2017-5462P4MEDIUMCVSS 5.3fixed in 52.1.0≥ unspecified, < 52.12018-06-11
CVE-2017-5462 [MEDIUM] CWE-682 CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the intern A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fir
nvd
CVE-2022-45411P4MEDIUMCVSS 6.1fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45411 [MEDIUM] CWE-79 CVE-2022-45411: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an X Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-sta
nvdosv
CVE-2024-10461P4MEDIUMCVSS 6.1fixed in 128.4.0≥ 129.0, < 132.0+2 more2024-10-29
CVE-2024-10461 [MEDIUM] CWE-79 CVE-2024-10461: In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
Mozilla Thunderbird vulnerabilities | cvebase