cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 98 of 101
CVE-2025-0240P4MEDIUMCVSS 4.0fixed in 128.6.0≥ 129.0, < 134.02025-01-07
CVE-2025-0240 [MEDIUM] CWE-416 CVE-2025-0240: Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2009-1305P4MEDIUMCVSS 5.0≤ 2.0.0.19v1.0+37 more2009-04-22
CVE-2009-1305 [MEDIUM] CWE-399 CVE-2009-1305: The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey be The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.
nvd
CVE-2004-2226P4MEDIUMCVSS 5.0v0.8v1.7.1+1 more2004-12-31
CVE-2004-2226 [MEDIUM] CVE-2004-2226: Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style Sheets (CSS) document on the attacker's server.
nvd
CVE-2008-5511P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.192008-12-17
CVE-2008-5511 [MEDIUM] CWE-79 CVE-2008-5511: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."
nvd
CVE-2013-1723P4MEDIUMCVSS 4.3≤ 17.0.9v17.0+8 more2013-09-18
CVE-2013-1723 [MEDIUM] CWE-119 CVE-2013-1723: The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2 The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 processes key messages after destruction by a dispatched event listener, which allows remote attackers to cause a denial of service (application crash) by leveraging incorrect event usage after widget-memory reallocation.
nvd
CVE-2008-5513P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.192008-12-17
CVE-2008-5513 [MEDIUM] CWE-79 CVE-2008-5513: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
nvd
CVE-2010-0171P4MEDIUMCVSS 4.3≤ 3.0.1v1.5+30 more2010-03-25
CVE-2010-0171 [MEDIUM] CVE-2010-0171: Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this v
nvd
CVE-2011-3648P4MEDIUMCVSS 4.3≤ 3.1.5v0.1+87 more2011-11-09
CVE-2011-3648 [MEDIUM] CWE-79 CVE-2011-3648: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Th Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.
nvd
CVE-2020-6792P4MEDIUMCVSS 4.3fixed in 68.5.0≥ unspecified, < 68.52020-03-02
CVE-2020-6792 [MEDIUM] CWE-908 CVE-2020-6792: When deriving an identifier for an email message, uninitialized memory was used in addition to the m When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5.
nvdosv
CVE-2004-0907P4MEDIUMCVSS 4.6v0.1v0.2+7 more2004-12-31
CVE-2004-0907 [MEDIUM] CVE-2004-0907: The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1. The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.
nvd
CVE-2014-1560P4MEDIUMCVSS 4.3≤ 24.7v24.0+8 more2014-07-23
CVE-2014-1560 [MEDIUM] CVE-2014-1560: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use ASCII character encoding in a required context.
nvdosv
CVE-2002-2436P4MEDIUMCVSS 4.3≤ 3.1.16v3.0+27 more2011-12-07
CVE-2002-2436 [MEDIUM] CWE-200 CVE-2002-2436: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3. The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
nvd
CVE-2011-2999P4MEDIUMCVSS 4.3≤ 5.0v0.1+95 more2011-09-29
CVE-2011-2999 [MEDIUM] CVE-2011-2999: Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.
nvd
CVE-2021-29957P4MEDIUMCVSS 4.3fixed in 78.10.2≥ unspecified, < 78.10.22021-06-24
CVE-2021-29957 [MEDIUM] CVE-2021-29957: If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contai If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.
nvdosv
CVE-2013-0776P4MEDIUMCVSS 4.0fixed in 17.0.32013-02-19
CVE-2013-0776 [MEDIUM] CWE-295 CVE-2013-0776: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server that provides a 407 HTTP status code accompanied by web script, as demonstrated by a phishing attack on an HTTPS site
nvd
CVE-2006-0298P4MEDIUMCVSS 5.8≥ 0, < 1.5.0.2-12006-02-02
CVE-2006-0298 [MEDIUM] CVE-2006-0298: The XML parser in Mozilla Firefox before 1 The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
osv
CVE-2022-1520P4MEDIUMCVSS 4.3fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-1520 [MEDIUM] CWE-346 CVE-2022-1520: When viewing an email message A, which contains an attached message B, where B is encrypted or digit When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This
nvdosv
CVE-2007-0775P4LOWCVSS 3.7v1.0.3v1.0.4+5 more2007-02-26
CVE-2007-0775 [LOW] CVE-2007-0775: Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.
nvd
CVE-2024-3861P4MEDIUMCVSS 4.0fixed in 115.0≥ unspecified, < 115.102024-04-16
CVE-2024-3861 [MEDIUM] CWE-416 CVE-2024-3861: If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect r If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2006-6499P4MEDIUMCVSS 4.3fixed in 1.5.0.92006-12-20
CVE-2006-6499 [MEDIUM] CWE-835 CVE-2006-6499: The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.
nvd