VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-4729
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2025-1010
Use-after-free in Custom Highlight
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2025-14326
Use-after-free in the Audio/Video: GMP component
Published 2025-12-09 · Modified
9.8EPSS 0.005
CVE-2026-5735
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.005
CVE-2026-0892
Memory safety bugs fixed in Firefox 147 and Thunderbird 147
Published 2026-01-13 · Modified
9.8EPSS 0.005
CVE-2026-2786
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-1012
Use-after-free during concurrent delazification
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2025-9187
Memory safety bugs fixed in Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2025-8044
Memory safety bugs fixed in Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2026-2782
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2026-16369
Integer overflow in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16363
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-2780
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2025-11709
Out of bounds read/write in a privileged process triggered by WebGL textures
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-11710
Cross-process information leaked due to malicious IPC messages
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-16350
Incorrect boundary conditions in the Audio/Video: cubeb component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16355
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16357
Incorrect boundary conditions in the Graphics component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16351
Sandbox escape due to use-after-free in the DOM: Navigation component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16356
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16352
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2024-10468
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
Published 2024-10-29 · Analyzed
9.8EPSS 0.004
CVE-2026-16368
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16383
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16377
Mitigation bypass in the PDF Viewer component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-8043
Incorrect URL truncation
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2026-84136
Other issue in the DOM: Navigation component
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-84143
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-16382
Mitigation bypass in the DOM: Service Workers component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16388
Sandbox escape in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-11721
Memory safety bug fixed in Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-11719
Use-after-free caused by the native messaging web extension API on Windows
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-84139
Clickjacking issue in the DOM: Events component
Published 2026-09-01 · Modified
9.8EPSS 0.003
CVE-2026-16402
Integer overflow in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2026-16361
Memory safety bugs fixed in Thunderbird ESR 140.13
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2026-16410
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2026-12293
Use-after-free in the Graphics: WebGPU component
Published 2026-06-16 · Modified
9.8EPSS 0.003
CVE-2026-84129
Site isolation issue in the DOM: Navigation component
Published 2026-09-01 · Analyzed
9.8EPSS 0.003
CVE-2026-84133
Site isolation issue in the DOM: Push Subscriptions component
Published 2026-09-01 · Analyzed
9.8EPSS 0.003
CVE-2026-84140
Site isolation issue in the DOM: Navigation component
Published 2026-09-01 · Modified
9.8EPSS 0.003
← Prev11 / 48Next →