VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2011-3647
The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.
Published 2011-11-09 · Modified
9.3EPSS 0.019
CVE-2020-12420
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
Published 2020-07-09 · Modified
9.3EPSS 0.019
CVE-2020-26960
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Published 2020-12-09 · Modified
9.3EPSS 0.016
CVE-2020-26968
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Published 2020-12-09 · Modified
9.3EPSS 0.015
CVE-2020-15656
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Published 2020-08-10 · Modified
9.3EPSS 0.015
CVE-2020-26970
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
Published 2020-12-09 · Modified
9.3EPSS 0.012
CVE-2020-12406
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Published 2020-07-09 · Modified
9.3EPSS 0.010
CVE-2026-8950
Same-origin policy bypass in the Networking: HTTP component
Published 2026-05-19 · Analyzed
9.3EPSS 0.002
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
9.11 PoCEPSS 0.185
CVE-2017-5447
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
9.11 PoCEPSS 0.173
CVE-2014-1508
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.
Published 2014-03-19 · Modified
9.1EPSS 0.043
CVE-2017-7753
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Published 2018-06-11 · Modified
9.1EPSS 0.031
CVE-2017-7758
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
9.1EPSS 0.031
CVE-2024-11705
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
9.1EPSS 0.007
CVE-2024-7522
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.1EPSS 0.006
CVE-2026-92240
Out-of-bounds read in IMAP response parser
Published 2026-09-15 · Analyzed
9.1EPSS 0.006
CVE-2024-7525
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.1EPSS 0.006
CVE-2026-2806
Uninitialized memory in the Graphics: Text component
Published 2026-02-24 · Modified
9.1EPSS 0.006
CVE-2026-74986
Site isolation issue in the CSS Parsing and Computation component
Published 2026-08-18 · Analyzed
9.1EPSS 0.006
CVE-2026-74956
Same-origin policy bypass in the DOM: Service Workers component
Published 2026-08-18 · Analyzed
9.1EPSS 0.005
CVE-2026-74959
Mitigation bypass in the Storage: Cache API component
Published 2026-08-18 · Analyzed
9.1EPSS 0.005
CVE-2026-8948
Same-origin policy bypass in the DOM: Networking component
Published 2026-05-19 · Modified
9.1EPSS 0.005
CVE-2025-4083
Process isolation bypass using "javascript:" URI links in cross-origin frames
Published 2025-04-29 · Modified
9.1EPSS 0.005
CVE-2026-74961
Side-channel in the Web Audio component
Published 2026-08-18 · Undergoing Analysis
9.1EPSS 0.004
CVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Published 2026-08-18 · Analyzed
9.1EPSS 0.004
CVE-2026-4724
Undefined behavior in the Audio/Video component
Published 2026-03-24 · Modified
9.1EPSS 0.004
CVE-2026-16392
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.1EPSS 0.004
CVE-2026-84639
Uninitialized memory in MIME parsing
Published 2026-09-01 · Analyzed
9.1EPSS 0.003
CVE-2026-16390
Mitigation bypass in the Enterprise Policies component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16370
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16380
Mitigation bypass in the Networking component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16364
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16393
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16359
Incorrect boundary conditions in the Audio/Video: GMP component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-12315
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
9.1EPSS 0.003
CVE-2026-12316
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
9.1EPSS 0.002
CVE-2025-8037
Nameless cookies shadow secure cookies
Published 2025-07-22 · Modified
9.1EPSS 0.002
CVE-2026-12304
Same-origin policy bypass in the Networking: Cookies component
Published 2026-06-16 · Analyzed
9.1EPSS 0.002
CVE-2026-16381
Same-origin policy bypass in the Networking: DNS component
Published 2026-07-21 · Analyzed
9.1EPSS 0.002
CVE-2023-4863
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Published 2023-09-12 · Analyzed
8.8KEVEPSS 1.000
← Prev16 / 44Next →