Mozilla Thunderbird vulnerabilities
2,009 known vulnerabilities affecting mozilla/thunderbird.
Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11
Vulnerabilities
Page 97 of 101
CVE-2025-1019P4MEDIUMCVSS 4.3≥ 131.0, < 135.02025-02-04
CVE-2025-1019 [MEDIUM] CWE-1021 CVE-2025-1019: The z-order of the browser windows could be manipulated to hide the fullscreen notification. This co
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2024-6610P4MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6610 [MEDIUM] CWE-451 CVE-2024-6610: Form validation popups could capture escape key presses. Therefore, spamming form validation message
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0749 [MEDIUM] CWE-346 CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
nvdosv
CVE-2025-1935P4MEDIUMCVSS 4.3fixed in 128.8.0≥ 129.0, < 136.02025-03-04
CVE-2025-1935 [MEDIUM] CWE-79 CVE-2025-1935: A web page could trick a user into setting that site as the default handler for a custom URL protoco
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2025-5266P4MEDIUMCVSS 4.3≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5266 [MEDIUM] CVE-2025-5266: Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
osv
CVE-2025-5263P4MEDIUMCVSS 4.3≥ 0, < 1:128.11.0esr-1~deb11u1≥ 0, < 1:128.11.0esr-1~deb12u1+1 more2025-05-27
CVE-2025-5263 [MEDIUM] CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
osv
CVE-2026-2802P4MEDIUMCVSS 4.2fixed in 148.02026-02-24
CVE-2026-2802 [MEDIUM] CWE-362 CVE-2026-2802: Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thun
Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2009-1304P4MEDIUMCVSS 5.0≤ 2.0.0.19v1.0+37 more2009-04-22
CVE-2009-1304 [MEDIUM] CWE-399 CVE-2009-1304: The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonke
The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.
nvd
CVE-2009-1303P4MEDIUMCVSS 5.0≤ 2.0.0.21v0.1+67 more2009-04-22
CVE-2009-1303 [MEDIUM] CWE-16 CVE-2009-1303: The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey befor
The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.
nvd
CVE-2008-1234P4MEDIUMCVSS 4.3≤ 2.0.0.122008-03-27
CVE-2008-1234 [MEDIUM] CWE-79 CVE-2008-1234: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."
nvd
CVE-2016-5250P4MEDIUMCVSS 4.3≥ 0, < 1:45.4.0+build1-0ubuntu0.14.04.1≥ 0, < 1:45.4.0+build1-0ubuntu0.16.04.12016-10-27
CVE-2016-5250 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Catalin Dumitru discovered that URLs of resources loaded after a
navigation start could be leaked to the following page via the Resource
Timing API. If a user were tricked in to opening a specially crafted
website in a browsing context, an attacker could potentially exploit this
to obtain sensitive information. (CVE-2016-5250)
Christoph Diehl, Andrew McCreight, Dan Minor, Byron Campen, Jon Coppeard,
Steve Fink, Tyso
osv
CVE-2008-0415P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-08
CVE-2008-0415 [MEDIUM] CWE-79 CVE-2008-0415: Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remo
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
nvd
CVE-2016-1957P4MEDIUMCVSS 4.3≤ 38.6.02016-03-13
CVE-2016-1957 [MEDIUM] CWE-119 CVE-2016-1957: Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
nvd
CVE-2008-0416P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-12
CVE-2008-0416 [MEDIUM] CWE-79 CVE-2008-0416: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-l
nvd
CVE-2012-4192P4MEDIUMCVSS 4.3v16.02012-10-12
CVE-2012-4192 [MEDIUM] CWE-264 CVE-2012-4192: Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same
Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
nvd
CVE-2006-4340P4MEDIUMCVSS 4.0≤ 1.5.0.62006-09-15
CVE-2006-4340 [MEDIUM] CWE-20 CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulner
nvdosv
CVE-2021-23968P4MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23968 [MEDIUM] CWE-209 CVE-2021-23968: If Content Security Policy blocked frame navigation, the full destination of a redirect served in th
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvdosv
CVE-2011-3001P4MEDIUMCVSS 4.3≤ 6.0.2v0.1+96 more2011-09-29
CVE-2011-3001 [MEDIUM] CWE-264 CVE-2011-3001: Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manua
Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.
nvd
CVE-2020-12397P4MEDIUMCVSS 4.3fixed in 68.8.0≥ unspecified, < 68.8.02020-05-22
CVE-2020-12397 [MEDIUM] CWE-346 CVE-2020-12397: By encoding Unicode whitespace characters within the From email header, an attacker can spoof the se
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
nvdosv
CVE-2006-5464P4MEDIUMCVSS 5.0v1.5v1.5.0.1+5 more2006-11-08
CVE-2006-5464 [MEDIUM] CVE-2006-5464: Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunder
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
nvd