cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 89 of 101
CVE-2012-1960P4MEDIUMCVSS 5.0v5.0v6.0+15 more2012-07-18
CVE-2012-1960 [MEDIUM] CWE-200 CVE-2012-1960: The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation.
nvd
CVE-2011-1187P4MEDIUMCVSS 5.0fixed in 12.02011-03-11
CVE-2011-1187 [MEDIUM] CWE-200 CVE-2011-1187: Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspe Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2016-5294P4MEDIUMCVSS 5.5fixed in 45.5.0≥ unspecified, < 45.52018-06-11
CVE-2016-5294 [MEDIUM] CWE-20 CVE-2016-5294: The Mozilla Updater can be made to choose an arbitrary target working directory for output files res The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2019-9817P4MEDIUMCVSS 5.3fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9817 [MEDIUM] CWE-346 CVE-2019-9817: Images from a different domain can be read using a canvas object in some circumstances. This could b Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
CVE-2011-2986P4MEDIUMCVSS 5.0≤ 5.0v0.1+79 more2011-08-18
CVE-2011-2986 [MEDIUM] CWE-200 CVE-2011-2986: Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other pr Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.
nvd
CVE-2011-3653P4MEDIUMCVSS 5.0≤ 7.0.1v0.1+93 more2011-11-09
CVE-2011-3653 [MEDIUM] CWE-200 CVE-2011-3653: Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.
nvd
CVE-2012-3986P4MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3986 [MEDIUM] CWE-20 CVE-2012-3986: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
nvd
CVE-2025-4089P4MEDIUMCVSS 5.1fixed in 138.02025-04-29
CVE-2025-4089 [MEDIUM] CWE-77 CVE-2025-4089: Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvdosv
CVE-2026-12311P4MEDIUMCVSS 4.7fixed in 152.0.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12311 [MEDIUM] CWE-200 CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerabi Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2010-3178P4MEDIUMCVSS 5.8≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3178 [MEDIUM] CWE-264 CVE-2010-3178: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1 Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers to bypass the Same Origin Policy vi
nvd
CVE-2014-1586P4MEDIUMCVSS 5.0v31.0v31.1.02014-10-15
CVE-2014-1586 [MEDIUM] CVE-2014-1586: content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Th content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigate
nvdosv
CVE-2014-1585P4MEDIUMCVSS 5.0v31.0v31.1.02014-10-15
CVE-2014-1585 [MEDIUM] CVE-2014-1585: The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firef The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not properly recognize Stop Sharing actions for videos in IFRAME elements, which allows remote attackers to obtain sensitive information from the local camera by maintaining a session after the user
nvdosv
CVE-2012-0456P4MEDIUMCVSS 5.0≥ 1.0, ≤ 3.1.19≤ 10.02012-03-14
CVE-2012-0456 [MEDIUM] CWE-200 CVE-2012-0456: The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10 The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds rea
nvd
CVE-2013-1693P4MEDIUMCVSS 4.3≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1693 [MEDIUM] CWE-264 CVE-2013-1693: The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunde The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.
nvd
CVE-2012-0447P4MEDIUMCVSS 5.0v5.0v6.0+5 more2012-02-01
CVE-2012-0447 [MEDIUM] CWE-200 CVE-2012-0447: Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not proper Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
nvd
CVE-2006-3810P4MEDIUMCVSS 6.8v1.5v1.5.0.2+1 more2006-07-27
CVE-2006-3810 [MEDIUM] CVE-2006-3810: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1 Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct.
nvdosv
CVE-2017-5414P4MEDIUMCVSS 5.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5414 [MEDIUM] CWE-200 CVE-2017-5414: The file picker dialog can choose and display the wrong local default directory when instantiated. O The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvd
CVE-2015-2721P4MEDIUMCVSS 4.3≥ 0, < 1:31.8.0+build1-0ubuntu0.14.04.12015-07-20
CVE-2015-2721 [MEDIUM] thunderbird vulnerabilities thunderbird vulnerabilities Karthikeyan Bhargavan discovered that NSS incorrectly handled state transitions for the TLS state machine. If a remote attacker were able to perform a machine-in-the-middle attack, this flaw could be exploited to skip the ServerKeyExchange message and remove the forward-secrecy property. (CVE-2015-2721) Bob Clary, Christian Holler, Bobby Holley, and Andrew McCreight discovered multiple memory safety issues in Thunde
osv
CVE-2023-4054P4MEDIUMCVSS 5.5≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4054 [MEDIUM] CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious c When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
nvdosv
CVE-2015-4519P4MEDIUMCVSS 4.3≥ 0, < 1:38.3.0+build1-0ubuntu0.14.04.12015-09-22
CVE-2015-4519 [MEDIUM] CVE-2015-4519: Mozilla Firefox before 41 Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.
osv
Mozilla Thunderbird vulnerabilities | cvebase