cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 95 of 101
CVE-2023-29533P4MEDIUMCVSS 4.3fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29533 [MEDIUM] CVE-2023-29533: A website could have obscured the fullscreen notification by using a combination of <code>window.ope A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thun
nvdosv
CVE-2022-3034P4MEDIUMCVSS 4.3fixed in 91.31.1≥ 102.0, < 102.2.1+2 more2022-12-22
CVE-2022-3034 [MEDIUM] CWE-1021 CVE-2022-3034: When receiving an HTML email that specified to load an <code>iframe</code> element from a remote loc When receiving an HTML email that specified to load an iframe element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
nvdosv
CVE-2024-4767P4MEDIUMCVSS 4.3fixed in 115.11.0≥ unspecified, < 115.112024-05-14
CVE-2024-4767 [MEDIUM] CWE-459 CVE-2024-4767: If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvdosv
CVE-2024-11701P4MEDIUMCVSS 4.3fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11701 [MEDIUM] CWE-290 CVE-2024-11701: The incorrect domain may have been displayed in the address bar during an interrupted navigation att The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvd
CVE-2024-11159P4MEDIUMCVSS 4.3fixed in 128.4.3≥ 129.0, < 132.0.1+2 more2024-11-13
CVE-2024-11159 [MEDIUM] CWE-312 CVE-2024-11159: Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vul Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
nvdosv
CVE-2026-0887P4MEDIUMCVSS 4.3fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0887 [MEDIUM] CWE-497 CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvdosv
CVE-2026-12303P4MEDIUMCVSS 4.3fixed in 152.0.02026-06-16
CVE-2026-12303 [MEDIUM] CWE-125 CVE-2026-12303: Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2022-36315P4MEDIUMCVSS 4.3≥ 0, < 1:102.2.2+build1-0ubuntu0.20.04.1≥ 0, < 1:102.2.2+build1-0ubuntu0.22.04.12022-07-27
CVE-2022-36315 [MEDIUM] CVE-2022-36315: When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with inc When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.
osv
CVE-2026-12320P4MEDIUMCVSS 4.3fixed in 152.0.02026-06-16
CVE-2026-12320 [MEDIUM] CWE-200 CVE-2026-12320: Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 15 Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2006-3802P4MEDIUMCVSS 5.8v1.5v1.5.0.2+1 more2006-07-27
CVE-2006-3802 [MEDIUM] CVE-2006-3802: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.
nvdosv
CVE-2008-5016P4MEDIUMCVSS 5.0≤ 2.0.0.17v2.0.0.0+6 more2008-11-13
CVE-2008-5016 [MEDIUM] CWE-399 CVE-2008-5016: The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonke The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.
nvd
CVE-2012-4194P4MEDIUMCVSS 4.3fixed in 16.0.22012-10-29
CVE-2012-4194 [MEDIUM] CWE-79 CVE-2012-4194: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors inv
nvd
CVE-2009-4629P4MEDIUMCVSS 5.0v3.0.12010-01-29
CVE-2009-4629 [MEDIUM] CWE-200 CVE-2009-4629: Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetc Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote attackers to determine the network location of the application's user by logging DNS requests, as demonstrated by DNS requests triggered by reading text/pl
nvd
CVE-2012-4209P4MEDIUMCVSS 4.3fixed in 17.02012-11-21
CVE-2012-4209 [MEDIUM] CWE-79 CVE-2012-4209: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a b
nvd
CVE-2012-3994P4MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3994 [MEDIUM] CWE-79 CVE-2012-3994: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the
nvd
CVE-2018-5161P4MEDIUMCVSS 4.3fixed in 52.8.0≥ unspecified, < 52.82018-06-11
CVE-2018-5161 [MEDIUM] CWE-20 CVE-2018-5161: Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulne Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvdosv
CVE-2010-2769P4MEDIUMCVSS 4.3≤ 3.0.6v0.1+66 more2010-09-09
CVE-2010-2769 [MEDIUM] CWE-79 CVE-2010-2769: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Th Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
nvd
CVE-2012-0471P4MEDIUMCVSS 4.3v5.0v6.0+13 more2012-04-25
CVE-2012-0471 [MEDIUM] CWE-79 CVE-2012-0471: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x befor Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.
nvd
CVE-2012-0477P4MEDIUMCVSS 4.3v5.0v6.0+13 more2012-04-25
CVE-2012-0477 [MEDIUM] CWE-79 CVE-2012-0477: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) ISO-2022-KR or (2) ISO-2022-CN character set.
nvd
CVE-2011-3000P4MEDIUMCVSS 4.3≤ 6.0.2v0.1+96 more2011-09-29
CVE-2011-3000 [MEDIUM] CWE-94 CVE-2011-3000: Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
nvd
Mozilla Thunderbird vulnerabilities | cvebase