Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 93 of 101
CVE-2025-6434P4MEDIUMCVSS 4.3≥ 0, < 1:140.7.1+build1-0ubuntu0.22.04.12025-06-24
CVE-2025-6434 [MEDIUM] CVE-2025-6434: The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140.
osv
CVE-2026-0818P4MEDIUMCVSS 4.3fixed in 140.7.1fixed in 147.0.12026-01-28
CVE-2026-0818 [MEDIUM] CWE-116 CVE-2026-0818: When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote
nvdosv
CVE-2013-1726P4MEDIUMCVSS 6.2≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1726 [MEDIUM] CWE-264 CVE-2013-1726: Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 2
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
nvd
CVE-2008-4065P4MEDIUMCVSS 4.3fixed in 2.0.0.172008-09-24
CVE-2008-4065 [MEDIUM] CWE-79 CVE-2008-4065: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey bef
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."
nvd
CVE-2004-0762P4MEDIUMCVSS 5.0≤ 0.72004-08-18
CVE-2004-0762 [MEDIUM] CVE-2004-0762: Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to instal
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
nvd
CVE-2004-0909P4MEDIUMCVSS 5.1v0.1v0.2+7 more2004-12-31
CVE-2004-0909 [MEDIUM] CVE-2004-0909: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may all
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
nvd
CVE-2005-0590P4MEDIUMCVSS 5.0v0.1v0.2+11 more2005-05-02
CVE-2005-0590 [MEDIUM] CVE-2005-0590: The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
nvd
CVE-2022-3266P4MEDIUMCVSS 5.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-3266 [MEDIUM] CWE-125 CVE-2022-3266: An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvdosv
CVE-2024-6613P4MEDIUMCVSS 5.5fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6613 [MEDIUM] CWE-209 CVE-2024-6613: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2012-3992P4MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3992 [MEDIUM] CWE-79 CVE-2012-3992: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and hi
nvd
CVE-2012-0451P4MEDIUMCVSS 4.3v5.0v6.0+7 more2012-03-14
CVE-2012-0451 [MEDIUM] CWE-94 CVE-2012-0451: CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP head
nvd
CVE-2013-0793P4MEDIUMCVSS 4.3v17.0v17.0.1+3 more2013-04-03
CVE-2013-0793 [MEDIUM] CWE-79 CVE-2013-0793: Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird
Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over naviga
nvd
CVE-2012-1961P4MEDIUMCVSS 4.3v5.0v6.0+15 more2012-07-18
CVE-2012-1961 [MEDIUM] CWE-20 CVE-2012-1961: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly handle duplicate values in X-Frame-Options headers, which makes it easier for remote attackers to conduct clickjacking attacks via a FRAME element referencing a web site that produ
nvd
CVE-2010-2768P4MEDIUMCVSS 4.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2768 [MEDIUM] CWE-79 CVE-2010-2768: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
nvd
CVE-2013-1714P4MEDIUMCVSS 4.3≤ 17.0.7v17.0+6 more2013-08-07
CVE-2013-1714 [MEDIUM] CWE-264 CVE-2013-1714: The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thund
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspec
nvd
CVE-2012-1957P4MEDIUMCVSS 4.3v5.0v6.0+15 more2012-07-18
CVE-2012-1957 [MEDIUM] CWE-79 CVE-2012-1957: An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.
An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly handle EMBED elements within description elements in RSS feeds, which allows remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2013-1692P4MEDIUMCVSS 4.3≤ 17.0.6v17.0+5 more2013-06-26
CVE-2013-1692 [MEDIUM] CWE-264 CVE-2013-1692: Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderb
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.
nvd
CVE-2014-2018P4MEDIUMCVSS 4.3v17.0v17.0.1+7 more2014-02-17
CVE-2014-2018 [MEDIUM] CVE-2014-2018: Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in a (1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.
nvd
CVE-2010-2764P4MEDIUMCVSS 4.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2764 [MEDIUM] CWE-264 CVE-2010-2764: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin requests.
nvd
CVE-2018-12367P4MEDIUMCVSS 4.3fixed in 60.0≥ unspecified, < 602018-10-18
CVE-2018-12367 [MEDIUM] CWE-20 CVE-2018-12367: In the previous mitigations for Spectre, the resolution or precision of various methods was reduced
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Fire
nvdosv