Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 9 of 101
CVE-2026-4702P3CRITICALCVSS 9.8≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4702 [CRITICAL] CVE-2026-4702: JIT miscompilation in the JavaScript Engine component
JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-8091P3CRITICALCVSS 9.8≥ 140.0, < 140.10.12026-05-07
CVE-2026-8091 [CRITICAL] CWE-754 CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
nvd
CVE-2026-2763P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2763 [CRITICAL] CWE-416 CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fire
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2770P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2770 [CRITICAL] CWE-416 CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148,
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2764P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2764 [CRITICAL] CWE-416 CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was f
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2025-14330P3CRITICALCVSS 9.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14330 [CRITICAL] CWE-119 CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvdosv
CVE-2025-8031P3CRITICALCVSS 9.8fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8031 [CRITICAL] CWE-276 CVE-2025-8031: The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvdosv
CVE-2026-4721P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4721 [CRITICAL] CWE-120 CVE-2026-4721: Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Fire
nvdosv
CVE-2026-16389P3CRITICALCVSS 9.8fixed in 153.02026-07-21
CVE-2026-16389 [CRITICAL] CWE-190 CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerabilit
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-4705P3CRITICALCVSS 9.8≥ 0, < 1:140.9.0esr-1~deb11u1≥ 0, < 1:140.9.0esr-1~deb12u1+2 more2026-03-24
CVE-2026-4705 [CRITICAL] CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component
Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
osv
CVE-2026-2788P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2788 [CRITICAL] CWE-119 CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-4710P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4710 [CRITICAL] CWE-119 CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdosv
CVE-2026-2787P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2787 [CRITICAL] CWE-416 CVE-2026-2787: Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 14
Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2759P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2759 [CRITICAL] CWE-1384 CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in F
Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvdosv
CVE-2026-2793P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2793 [CRITICAL] CWE-787 CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fire
nvdosv
CVE-2020-15663P3HIGHCVSS 8.8≥ 68.0, < 68.12≥ 78.0, < 78.2+2 more2020-10-01
CVE-2020-15663 [HIGH] CWE-427 CVE-2020-15663: If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute
If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation
nvd
CVE-2025-6427P3CRITICALCVSS 9.1≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6427 [CRITICAL] CVE-2025-6427: An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.
osv
CVE-2012-0469P3CRITICALCVSS 10.0v5.0v6.0+13 more2012-04-25
CVE-2012-0469 [CRITICAL] CWE-399 CVE-2012-0469: Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace fun
Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted Inde
nvd
CVE-2021-44538P3CRITICALCVSS 9.8≥ 0, < 1:91.4.1-1~deb11u1≥ 0, < 1:91.4.1-12021-12-14
CVE-2021-44538 [CRITICAL] CVE-2021-44538: The olm_session_describe function in Matrix libolm before 3
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some bu
osv
CVE-2013-1732P3CRITICALCVSS 9.3≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1732 [CRITICAL] CWE-119 CVE-2013-1732: Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox
Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.
nvd