Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 90 of 101
CVE-2012-3975P4MEDIUMCVSS 4.3≤ 14.0v1.0+98 more2012-08-29
CVE-2012-3975 [MEDIUM] CWE-200 CVE-2012-3975: The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey befor
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.
nvd
CVE-2018-5170P4MEDIUMCVSS 4.3fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5170 [MEDIUM] CWE-20 CVE-2018-5170: It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2024-5691P4MEDIUMCVSS 4.7fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5691 [MEDIUM] CWE-693 CVE-2024-5691: By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a b
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvdosv
CVE-2012-1963P4MEDIUMCVSS 4.3v5.0v6.0+15 more2012-07-18
CVE-2012-1963 [MEDIUM] CWE-264 CVE-2012-1963: The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.
The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture O
nvd
CVE-2025-5264P4MEDIUMCVSS 4.8≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5264 [MEDIUM] CVE-2025-5264: Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potential
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139,
osv
CVE-2020-6797P4MEDIUMCVSS 4.3fixed in 68.5.0≥ unspecified, < 68.52020-03-02
CVE-2020-6797 [MEDIUM] CWE-20 CVE-2020-6797: By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbit
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating sy
nvd
CVE-2025-5265P4MEDIUMCVSS 4.8≥ 0, < 1:128.12.0+build1-0ubuntu0.22.04.12025-05-27
CVE-2025-5265 [MEDIUM] CVE-2025-5265: Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potenti
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerabil
osv
CVE-2024-6601P4MEDIUMCVSS 4.7fixed in 128.0≥ unspecified, < 115.13+1 more2024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosv
CVE-2026-12313P4MEDIUMCVSS 4.7fixed in 152.0.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12313 [MEDIUM] CWE-269 CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerabi
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2007-4038P4MEDIUMCVSS 4.3v1.52007-07-27
CVE-2007-4038 [MEDIUM] CVE-2007-4038: Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thu
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invokin
nvd
CVE-2010-3182P4MEDIUMCVSS 6.9≤ 3.0.8v0.1+70 more2010-10-21
CVE-2010-3182 [MEDIUM] CVE-2010-3182: A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
nvd
CVE-2006-1742P4MEDIUMCVSS 5.0≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1742 [MEDIUM] CVE-2006-1742: The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozi
The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.
nvdosv
CVE-2006-6503P4MEDIUMCVSS 6.8fixed in 1.5.0.92006-12-20
CVE-2006-6503 [MEDIUM] CWE-254 CVE-2006-6503: Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
nvd
CVE-2012-0473P4MEDIUMCVSS 5.0v5.0v6.0+13 more2012-04-25
CVE-2012-0473 [MEDIUM] CWE-189 CVE-2012-0473: The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x
The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from
nvd
CVE-2006-6502P4HIGHCVSS 7.1v0.1v0.2+27 more2006-12-20
CVE-2006-6502 [HIGH] CVE-2006-6502: Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1,
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.
nvd
CVE-2022-36314P4MEDIUMCVSS 5.5fixed in 102.1≥ unspecified, < 102.12022-12-22
CVE-2022-36314 [MEDIUM] CWE-427 CVE-2022-36314: When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path th
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
nvdosv
CVE-2012-4201P4MEDIUMCVSS 4.3fixed in 17.02012-11-21
CVE-2012-4201 [MEDIUM] CWE-79 CVE-2012-4201: The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Th
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during the handling of JavaScript code that sets the location.href property, which allows remote attackers to conduct cross-site scripting (XS
nvd
CVE-2002-2437P4MEDIUMCVSS 5.0≤ 3.1.16v3.0+27 more2011-12-07
CVE-2002-2437 [MEDIUM] CWE-264 CVE-2002-2437: The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey b
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
nvd
CVE-2015-0827P4MEDIUMCVSS 4.3≤ 31.4v31.0+3 more2015-02-25
CVE-2015-0827 [MEDIUM] CWE-119 CVE-2015-0827: Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Fi
Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.
nvdosv
CVE-2013-0748P4MEDIUMCVSS 4.3fixed in 17.0.22013-01-13
CVE-2013-0748 [MEDIUM] CWE-200 CVE-2013-0748: The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10
The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function
nvd