Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 82 of 101
CVE-2022-29911P4MEDIUMCVSS 6.1fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29911 [MEDIUM] CWE-1021 CVE-2022-29911: An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-acti
An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvdosv
CVE-2024-4768P4MEDIUMCVSS 6.1fixed in 115.11.0≥ unspecified, < 115.112024-05-14
CVE-2024-4768 [MEDIUM] CWE-281 CVE-2024-4768: A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a us
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvdosv
CVE-2024-1549P4MEDIUMCVSS 6.1fixed in 115.8.0≥ unspecified, < 115.82024-02-20
CVE-2024-1549 [MEDIUM] CVE-2024-1549: If a website set a large custom cursor, portions of the cursor could have overlapped with the permis
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvdosv
CVE-2024-11694P4MEDIUMCVSS 6.1fixed in 115.18.0≥ 116.0, < 128.5.0+4 more2024-11-26
CVE-2024-11694 [MEDIUM] CWE-79 CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass a
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ES
nvdosv
CVE-2025-13013P4MEDIUMCVSS 6.1≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13013 [MEDIUM] CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component
Mitigation bypass in the DOM: Core & HTML component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2017-7825P4MEDIUMCVSS 5.3fixed in 52.4.0≥ unspecified, < 52.42018-06-11
CVE-2017-7825 [MEDIUM] CWE-20 CVE-2017-7825: Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the add
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.
nvd
CVE-2025-1015P4MEDIUMCVSS 5.4≥ 128.0.1, < 128.7.02025-02-04
CVE-2025-1015 [MEDIUM] CWE-79 CVE-2025-1015: The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attack
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page insi
nvdosv
CVE-2020-6812P4MEDIUMCVSS 5.3fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6812 [MEDIUM] CWE-200 CVE-2020-6812: The first time AirPods are connected to an iPhone, they become named after the user's name by defaul
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to sim
nvdosv
CVE-2012-0445P4MEDIUMCVSS 5.0v5.0v6.0+5 more2012-02-01
CVE-2012-0445 [MEDIUM] CWE-264 CVE-2012-0445: Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote
Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation policy and replace arbitrary sub-frames by creating a form submission target with a sub-frame's name attribute.
nvd
CVE-2008-5012P4MEDIUMCVSS 5.0≤ 2.0.0.17v0.1+46 more2008-11-13
CVE-2008-5012 [MEDIUM] CWE-200 CVE-2008-5012: Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.1
Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue
nvd
CVE-2024-2611P4MEDIUMCVSS 5.5fixed in 115.9.0≥ unspecified, < 115.92024-03-19
CVE-2024-2611 [MEDIUM] CVE-2024-2611: A missing delay on when pointer lock was used could have allowed a malicious page to trick a user in
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvdosv
CVE-2019-11761P4MEDIUMCVSS 5.4fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvdosv
CVE-2022-36059P4MEDIUMCVSS 5.3≥ 0, < 1:102.2.1-12023-03-28
CVE-2022-36059 [MEDIUM] CVE-2022-36059: matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding
osv
CVE-2008-5512P4MEDIUMCVSS 6.8≥ 2.0, < 2.0.0.192008-12-17
CVE-2008-5512 [MEDIUM] CWE-264 CVE-2008-5512: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Th
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."
nvd
CVE-2024-11696P4MEDIUMCVSS 5.4fixed in 128.5.0≥ 129.0, < 133.0+2 more2024-11-26
CVE-2024-11696 [MEDIUM] CWE-347 CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated ad
nvdosv
CVE-2023-4045P4MEDIUMCVSS 5.3≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4045 [MEDIUM] CVE-2023-4045: Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2026-12298P4MEDIUMCVSS 5.4fixed in 152.0.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12298 [MEDIUM] CWE-125 CVE-2026-12298: Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-6774P4MEDIUMCVSS 5.4fixed in 150.02026-04-21
CVE-2026-6774 [MEDIUM] CWE-693 CVE-2026-6774: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Th
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-8391P4MEDIUMCVSS 5.3fixed in Thunderbird 140.11
CVE-2026-8391 [MEDIUM] Mozilla Foundation Security Advisory 2026-51: CVE-2026-8391
Mozilla Foundation Security Advisory 2026-51
CVE: CVE-2026-8391
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.11
mozilla
CVE-2007-3734P4CRITICALCVSS 9.3v2.0.0.0v2.0.0.1+3 more2007-07-18
CVE-2007-3734 [CRITICAL] CVE-2007-3734: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thu
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
nvd