VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2025-1017
Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2026-2800
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2805
Invalid pointer in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-4710
Incorrect boundary conditions in the Audio/Video component
Published 2026-03-24 · Modified
9.8EPSS 0.006
CVE-2026-84134
Other issue in the Profile Backup component
Published 2026-09-01 · Analyzed
9.8EPSS 0.006
CVE-2026-74989
Internally found bugs fixed in Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-2777
Privilege escalation in the Messaging System component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2025-9179
Sandbox escape due to invalid pointer in the Audio/Video: GMP component
Published 2025-08-19 · Modified
9.8EPSS 0.006
CVE-2026-2775
Mitigation bypass in the DOM: HTML Parser component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2025-14324
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
9.8EPSS 0.006
CVE-2026-16389
Incorrect boundary conditions, integer overflow in the Libraries component in NSS
Published 2026-07-21 · Modified
9.8EPSS 0.006
CVE-2026-84142
Internally found bugs fixed in Firefox 155
Published 2026-09-01 · Modified
9.8EPSS 0.006
CVE-2026-2781
Integer overflow in the Libraries component in NSS
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2025-1020
Memory safety bugs fixed in Firefox 135 and Thunderbird 135
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2026-92238
Ambiguous parsing of mail headers
Published 2026-09-15 · Analyzed
9.8EPSS 0.005
CVE-2026-2791
Mitigation bypass in the Networking: Cache component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2784
Mitigation bypass in the DOM: Security component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2024-9392
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
9.8EPSS 0.005
CVE-2026-74985
Privilege escalation in the Enterprise Policies component
Published 2026-08-18 · Analyzed
9.8EPSS 0.005
CVE-2026-6771
Mitigation bypass in the DOM: Security component
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Published 2026-08-18 · Analyzed
9.8EPSS 0.005
CVE-2026-16353
Invalid pointer in the DOM: Bindings (WebIDL) component
Published 2026-07-21 · Analyzed
9.8EPSS 0.005
CVE-2024-7528
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
Published 2024-08-06 · Analyzed
9.8EPSS 0.005
CVE-2026-6768
Mitigation bypass in the Networking: Cookies component
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2026-6760
Mitigation bypass in the Networking: Cookies component
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2025-8028
Large branch table could lead to truncated instruction
Published 2025-07-22 · Modified
9.8EPSS 0.005
CVE-2025-11708
Use-after-free in MediaTrackGraphImpl::GetInstance()
Published 2025-10-14 · Modified
9.8EPSS 0.005
CVE-2025-14330
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
9.8EPSS 0.005
CVE-2026-2807
Memory safety bugs fixed in Firefox 148 and Thunderbird 148
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2789
Use-after-free in the Graphics: ImageLib component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2787
Use-after-free in the DOM: Window and Location component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-0884
Use-after-free in the JavaScript Engine component
Published 2026-01-13 · Modified
9.8EPSS 0.005
CVE-2025-1942
Disclosure of uninitialized memory when .toUpperCase() causes string to get longer
Published 2025-03-04 · Modified
9.8EPSS 0.005
CVE-2026-2797
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2799
Use-after-free in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2795
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2021-43529
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Published 2023-02-16 · Modified
9.8EPSS 0.005
CVE-2026-16360
Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
Published 2026-07-21 · Analyzed
9.8EPSS 0.005
CVE-2026-2785
Invalid pointer in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-8031
Incorrect URL stripping in CSP reports
Published 2025-07-22 · Modified
9.8EPSS 0.005
← Prev10 / 48Next →