Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 92 of 101
CVE-2012-4208P4MEDIUMCVSS 4.3fixed in 17.02012-11-21
CVE-2012-4208 [MEDIUM] CWE-200 CVE-2012-4208: The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonke
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
nvd
CVE-2013-5595P4MEDIUMCVSS 4.3≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5595 [MEDIUM] CWE-119 CVE-2013-5595: The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x befor
The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly allocate memory for unspecified functions, which allows remote attackers to conduct buffer overflow attacks via a crafted web page.
nvd
CVE-2018-12374P4MEDIUMCVSS 4.3fixed in 52.9.0≥ unspecified, < 52.92018-10-18
CVE-2018-12374 [MEDIUM] CWE-200 CVE-2018-12374: Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
nvdosv
CVE-2013-5593P4MEDIUMCVSS 4.3≤ 24.0.1v17.0+9 more2013-10-30
CVE-2013-5593 [MEDIUM] CWE-20 CVE-2013-5593: The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thun
The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation o
nvd
CVE-2012-5841P4MEDIUMCVSS 4.3fixed in 17.02012-11-21
CVE-2012-5841 [MEDIUM] CWE-79 CVE-2012-5841: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
nvd
CVE-2012-3985P4MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3985 [MEDIUM] CWE-79 CVE-2012-3985: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly impl
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
nvd
CVE-2012-4195P4MEDIUMCVSS 4.3fixed in 16.0.22012-10-29
CVE-2012-4195 [MEDIUM] CWE-79 CVE-2012-4195: The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10,
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (X
nvd
CVE-2026-15718P4UNKNOWNfixed in Thunderbird 140.13
CVE-2026-15718 Mozilla Foundation Security Advisory 2026-72: CVE-2026-15718
Mozilla Foundation Security Advisory 2026-72
CVE: CVE-2026-15718
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.13
mozilla
CVE-2021-38506P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38506 [MEDIUM] CWE-1021 CVE-2021-38506: Through a series of navigations, Firefox could have entered fullscreen mode without notification or
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2020-26953P4MEDIUMCVSS 4.3fixed in 78.52020-12-09
CVE-2020-26953 [MEDIUM] CWE-1021 CVE-2020-26953: It was possible to cause the browser to enter fullscreen mode without displaying the security UI; th
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdosv
CVE-2020-35111P4MEDIUMCVSS 4.3fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-35111 [MEDIUM] CVE-2020-35111: When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest ca
When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdosv
CVE-2021-43538P4MEDIUMCVSS 4.3fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43538 [MEDIUM] CWE-362 CVE-2021-43538: By misusing a race in our notification code, an attacker could have forcefully hidden the notificati
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
CVE-2013-1672P4MEDIUMCVSS 6.9≤ 17.0.5v17.0+4 more2013-05-16
CVE-2013-1672 [MEDIUM] CWE-264 CVE-2013-1672: The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thun
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
nvd
CVE-2021-29956P4MEDIUMCVSS 4.3≥ 78.8.1, ≤ 78.10.1≥ unspecified, < 78.10.22021-06-24
CVE-2021-29956 [MEDIUM] CWE-312 CVE-2021-29956: OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were s
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using aff
nvdosv
CVE-2023-5721P4MEDIUMCVSS 4.3fixed in 115.4.1≥ unspecified, < 115.4.12023-10-25
CVE-2023-5721 [MEDIUM] CWE-1021 CVE-2023-5721: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvdosv
CVE-2022-22743P4MEDIUMCVSS 4.3fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22743 [MEDIUM] CVE-2022-22743: When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdosv
CVE-2024-0742P4MEDIUMCVSS 4.3fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0742 [MEDIUM] CVE-2024-0742: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2022-34472P4MEDIUMCVSS 4.3fixed in 91.11≥ unspecified, < 102+1 more2022-12-22
CVE-2022-34472 [MEDIUM] CWE-703 CVE-2022-34472: If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2023-4581P4MEDIUMCVSS 4.3fixed in 115.2≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4581 [MEDIUM] CVE-2023-4581: Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which all
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
nvdosv
CVE-2025-6425P4MEDIUMCVSS 4.3≥ 0, < 1:128.12.0esr-1~deb11u1≥ 0, < 1:128.12.0esr-1~deb12u1+1 more2025-06-24
CVE-2025-6425 [MEDIUM] CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted bet
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunder
osv