Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 84 of 101
CVE-2018-5117P4MEDIUMCVSS 5.3fixed in 52.6.0≥ unspecified, < 52.62018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvdosv
CVE-2018-5168P4MEDIUMCVSS 5.3fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvdosv
CVE-2024-8386P4MEDIUMCVSS 6.1≥ unspecified, < 128.22024-09-03
CVE-2024-8386 [MEDIUM] CWE-601 CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to a
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvdosv
CVE-2022-36316P4MEDIUMCVSS 6.1≥ 0, < 1:102.2.2+build1-0ubuntu0.20.04.1≥ 0, < 1:102.2.2+build1-0ubuntu0.22.04.12022-07-27
CVE-2022-36316 [MEDIUM] CVE-2022-36316: When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.
osv
CVE-2025-11712P4MEDIUMCVSS 6.1fixed in 140.4.0≥ 141.0, < 144.02025-10-14
CVE-2025-11712 [MEDIUM] CWE-116 CVE-2025-11712: A malicious page could have used the type attribute of an OBJECT tag to override the default browser
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunder
nvdosv
CVE-2025-6430P4MEDIUMCVSS 6.1≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6430 [MEDIUM] CVE-2025-6430: When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag,
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and
osv
CVE-2014-1491P4MEDIUMCVSS 4.3fixed in 24.3.02014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
CVE-2019-11717P4MEDIUMCVSS 5.3fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2006-6497P4MEDIUMCVSS 6.8≤ 1.5.0.82006-12-20
CVE-2006-6497 [MEDIUM] CVE-2006-6497: Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.
Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.
nvd
CVE-2006-6498P4MEDIUMCVSS 6.8v0.1v0.2+28 more2006-12-20
CVE-2006-6498 [MEDIUM] CVE-2006-6498: Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown impact
nvd
CVE-2017-7764P4MEDIUMCVSS 5.3fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7764 [MEDIUM] CWE-20 CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unico
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syl
nvd
CVE-2013-0759P4MEDIUMCVSS 5.0fixed in 17.0.22013-01-13
CVE-2013-0759 [MEDIUM] CWE-287 CVE-2013-0759: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to spoof the address bar via vectors involving authentication information in the userinfo field of a URL, in conjunction with a 204
nvd
CVE-2017-5426P4MEDIUMCVSS 5.3fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5426 [MEDIUM] CWE-732 CVE-2017-5426: On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plug
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems
nvd
CVE-2017-7763P4MEDIUMCVSS 5.3fixed in 52.2.0≥ unspecified, < 52.22018-06-11
CVE-2017-7763 [MEDIUM] CWE-20 CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2023-6206P4MEDIUMCVSS 5.4fixed in 115.5≥ unspecified, < 115.52023-11-21
CVE-2023-6206 [MEDIUM] CWE-1021 CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking dela
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvdosv
CVE-2024-11695P4MEDIUMCVSS 5.4fixed in 128.5.0≥ 129.0, < 133.0+2 more2024-11-26
CVE-2024-11695 [MEDIUM] CWE-1021 CVE-2024-11695: A crafted URL containing Arabic script and whitespace characters could have hidden the true origin o
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvdosv
CVE-2024-9398P4MEDIUMCVSS 5.3fixed in 128.3v129.0+2 more2024-10-01
CVE-2024-9398 [MEDIUM] CWE-203 CVE-2024-9398: By checking the result of calls to `window.open` with specifically set protocol handlers, an attacke
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvdosv
CVE-2026-12299P4MEDIUMCVSS 5.4fixed in 152.0.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12299 [MEDIUM] CWE-843 CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, F
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-0890P4MEDIUMCVSS 5.4fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0890 [MEDIUM] CWE-290 CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in F
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2025-10531P4MEDIUMCVSS 5.4fixed in 143.02025-09-16
CVE-2025-10531 [MEDIUM] CWE-288 CVE-2025-10531: Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firef
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd