cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 86 of 101
CVE-2017-5383P4MEDIUMCVSS 5.3fixed in 45.7.0≥ unspecified, < 45.72018-06-11
CVE-2017-5383 [MEDIUM] CWE-20 CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger pu URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2013-1737P4MEDIUMCVSS 5.0≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1737 [MEDIUM] CWE-264 CVE-2013-1737: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expan
nvd
CVE-2015-7197P4MEDIUMCVSS 5.0≥ 0, < 1:38.4.0+build3-0ubuntu0.14.04.12015-11-04
CVE-2015-7197 [MEDIUM] CVE-2015-7197: Mozilla Firefox before 42 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code.
osv
CVE-2019-9801P4MEDIUMCVSS 5.3fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9801 [MEDIUM] CWE-20 CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch th Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. O
nvd
CVE-2023-4046P4MEDIUMCVSS 5.3≥ 0, < 1:102.14.0-1~deb11u1≥ 0, < 1:102.14.0-1~deb12u1+1 more2023-08-01
CVE-2023-4046 [MEDIUM] CVE-2023-4046: In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
osv
CVE-2016-5291P4MEDIUMCVSS 5.5fixed in 45.5.0≥ unspecified, < 45.52018-06-11
CVE-2016-5291 [MEDIUM] CWE-20 CVE-2016-5291: A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. Thi A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2023-29479P4MEDIUMCVSS 5.3≥ 0, < 1:102.10.0-1~deb11u1≥ 0, < 1:102.10.0-12023-04-24
CVE-2023-29479 [MEDIUM] CVE-2023-29479: Ribose RNP before 0 Ribose RNP before 0.16.3 may hang when the input is malformed.
osv
CVE-2020-12392P4MEDIUMCVSS 5.5fixed in 68.8.0≥ unspecified, < 68.8.02020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
nvdosv
CVE-2022-28286P4MEDIUMCVSS 5.4fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28286 [MEDIUM] CWE-1021 CVE-2022-28286: Due to a layout change, iframe contents could have been rendered outside of its border. This could h Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvdosv
CVE-2023-25730P4MEDIUMCVSS 5.4fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25730 [MEDIUM] CWE-1021 CVE-2023-25730: A background script invoking <code>requestFullscreen</code> and then blocking the main thread could A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2010-0163P4MEDIUMCVSS 4.3≤ 2.0.0.23v0.1+56 more2010-03-23
CVE-2010-0163 [MEDIUM] CVE-2010-0163: Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a pa Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
nvd
CVE-2023-29532P4MEDIUMCVSS 5.5fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29532 [MEDIUM] CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local syste
nvd
CVE-2023-6857P4MEDIUMCVSS 5.3fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6857 [MEDIUM] CWE-362 CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be sma When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvdosv
CVE-2022-1197P4MEDIUMCVSS 5.4fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-1197 [MEDIUM] CWE-295 CVE-2022-1197: When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability a
nvdosv
CVE-2024-6612P4MEDIUMCVSS 5.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6612 [MEDIUM] CWE-200 CVE-2024-6612: CSP violations generated links in the console tab of the developer tools, pointing to the violating CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2025-5267P4MEDIUMCVSS 5.4≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5267 [MEDIUM] CVE-2025-5267: A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
osv
CVE-2026-12322P4MEDIUMCVSS 5.4fixed in 152.0.02026-06-16
CVE-2026-12322 [MEDIUM] CWE-1021 CVE-2026-12322: Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thu Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2026-12321P4MEDIUMCVSS 5.4fixed in 152.0.02026-06-16
CVE-2026-12321 [MEDIUM] CWE-670 CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2025-1018P4MEDIUMCVSS 5.3≥ 131.0, < 135.02025-02-04
CVE-2025-1018 [MEDIUM] CWE-1021 CVE-2025-1018: The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the use The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2026-6777P4MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6777 [MEDIUM] CWE-20 CVE-2026-6777: Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunde Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
Mozilla Thunderbird vulnerabilities | cvebase