VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2025-1942
Disclosure of uninitialized memory when .toUpperCase() causes string to get longer
Published 2025-03-04 · Modified
9.8EPSS 0.005
CVE-2026-2797
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2799
Use-after-free in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2795
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2021-43529
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Published 2023-02-16 · Modified
9.8EPSS 0.005
CVE-2026-16360
Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
Published 2026-07-21 · Analyzed
9.8EPSS 0.005
CVE-2026-2785
Invalid pointer in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-8031
Incorrect URL stripping in CSP reports
Published 2025-07-22 · Modified
9.8EPSS 0.005
CVE-2026-4729
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2025-1010
Use-after-free in Custom Highlight
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2025-14326
Use-after-free in the Audio/Video: GMP component
Published 2025-12-09 · Modified
9.8EPSS 0.005
CVE-2026-5735
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.005
CVE-2026-0892
Memory safety bugs fixed in Firefox 147 and Thunderbird 147
Published 2026-01-13 · Modified
9.8EPSS 0.005
CVE-2026-2786
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-1012
Use-after-free during concurrent delazification
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2025-9187
Memory safety bugs fixed in Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2025-8044
Memory safety bugs fixed in Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2026-2782
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2026-16363
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16369
Integer overflow in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-2780
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2025-11710
Cross-process information leaked due to malicious IPC messages
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-11709
Out of bounds read/write in a privileged process triggered by WebGL textures
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-16355
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16350
Incorrect boundary conditions in the Audio/Video: cubeb component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16357
Incorrect boundary conditions in the Graphics component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16356
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16352
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16351
Sandbox escape due to use-after-free in the DOM: Navigation component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2024-10468
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
Published 2024-10-29 · Analyzed
9.8EPSS 0.004
CVE-2026-16368
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16377
Mitigation bypass in the PDF Viewer component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16383
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-8043
Incorrect URL truncation
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2026-84136
Other issue in the DOM: Navigation component
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-16382
Mitigation bypass in the DOM: Service Workers component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-84143
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-16388
Sandbox escape in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-11721
Memory safety bug fixed in Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-11719
Use-after-free caused by the native messaging web extension API on Windows
Published 2025-10-14 · Modified
9.8EPSS 0.004
← Prev10 / 44Next →