Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 88 of 101
CVE-2026-12323P4MEDIUMCVSS 5.4fixed in 152.0.02026-06-16
CVE-2026-12323 [MEDIUM] CWE-1021 CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Th
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2024-10468P4MEDIUMCVSS 5.3fixed in 132.0≥ unspecified, < 1322024-10-29
CVE-2024-10468 [MEDIUM] CWE-362 CVE-2024-10468: Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
nvdosv
CVE-2025-4090P4MEDIUMCVSS 5.3fixed in 138.02025-04-29
CVE-2025-4090 [MEDIUM] CWE-532 CVE-2025-4090: A vulnerability existed in Thunderbird for Android where potentially sensitive library locations wer
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvd
CVE-2025-26695P4MEDIUMCVSS 5.3fixed in 128.8.0≥ 129.0, < 136.02025-03-10
CVE-2025-26695 [MEDIUM] CVE-2025-26695: When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network o
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
nvdosv
CVE-2012-4184P4MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-4184 [MEDIUM] CWE-79 CVE-2012-4184: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome pr
nvd
CVE-2010-0161P4MEDIUMCVSS 4.3≤ 2.0.0.23v0.1+52 more2010-03-23
CVE-2010-0161 [MEDIUM] CWE-399 CVE-2010-0161: The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.
The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted
nvd
CVE-2021-38509P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2011-3664P4MEDIUMCVSS 6.8≤ 8.0v0.1+98 more2011-12-21
CVE-2011-3664 [MEDIUM] CVE-2011-3664: Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not prop
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2025-4087P4MEDIUMCVSS 4.8fixed in 128.10.0fixed in 138.02025-04-29
CVE-2025-4087 [MEDIUM] CWE-125 CVE-2025-4087: A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior d
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbird 128.10.
nvdosv
CVE-2005-0255P4MEDIUMCVSS 5.0v0.1v0.2+8 more2005-05-02
CVE-2005-0255 [MEDIUM] CVE-2005-0255: String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the n
String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes
nvd
CVE-2019-11715P4MEDIUMCVSS 6.1fixed in 60.8.0≥ unspecified, < 60.82019-07-23
CVE-2019-11715 [MEDIUM] CWE-79 CVE-2019-11715: Due to an error while parsing page content, it is possible for properly sanitized user input to be m
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2019-11763P4MEDIUMCVSS 6.1fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11763 [MEDIUM] CWE-79 CVE-2019-11763: Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of e
nvdosv
CVE-2014-1565P4MEDIUMCVSS 5.0v31.02014-09-03
CVE-2014-1565 [MEDIUM] CWE-119 CVE-2014-1565: The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox
The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 does not properly create audio timelines, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) vi
nvdosv
CVE-2006-0236P4MEDIUMCVSS 5.1v1.0v1.0.1+5 more2006-01-18
CVE-2006-0236 [MEDIUM] CWE-94 CVE-2006-0236: GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assi
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to
nvd
CVE-2008-5510P4MEDIUMCVSS 5.0≥ 2.0, < 2.0.0.192008-12-17
CVE-2008-5510 [MEDIUM] CVE-2008-5510: The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
nvd
CVE-2014-1539P4MEDIUMCVSS 5.0≤ 24.6v24.0+7 more2014-06-11
CVE-2014-1539 [MEDIUM] CWE-20 CVE-2014-1539: Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cur
Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct clickjacking attacks via JavaScript code that produces a fake cursor image.
nvd
CVE-2020-12405P4MEDIUMCVSS 5.3fixed in 68.9.0≥ unspecified, < 68.9.02020-07-09
CVE-2020-12405 [MEDIUM] CWE-362 CVE-2020-12405: When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2008-0591P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-09
CVE-2008-0591 [MEDIUM] CVE-2008-0591: Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay tim
Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".
nvd
CVE-2019-9797P4MEDIUMCVSS 5.3≥ 0, < 1:60.7.0-12019-04-26
CVE-2019-9797 [MEDIUM] CVE-2019-9797: Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
osv
CVE-2017-7782P4MEDIUMCVSS 5.3fixed in 52.3.0≥ unspecified, < 52.32018-06-11
CVE-2017-7782 [MEDIUM] CWE-269 CVE-2017-7782: An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated b
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd