VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2024-7522
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.1EPSS 0.006
CVE-2026-92240
Out-of-bounds read in IMAP response parser
Published 2026-09-15 · Analyzed
9.1EPSS 0.006
CVE-2024-7525
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.1EPSS 0.006
CVE-2026-2806
Uninitialized memory in the Graphics: Text component
Published 2026-02-24 · Modified
9.1EPSS 0.006
CVE-2026-74986
Site isolation issue in the CSS Parsing and Computation component
Published 2026-08-18 · Analyzed
9.1EPSS 0.006
CVE-2026-74956
Same-origin policy bypass in the DOM: Service Workers component
Published 2026-08-18 · Analyzed
9.1EPSS 0.005
CVE-2026-74959
Mitigation bypass in the Storage: Cache API component
Published 2026-08-18 · Analyzed
9.1EPSS 0.005
CVE-2026-8948
Same-origin policy bypass in the DOM: Networking component
Published 2026-05-19 · Modified
9.1EPSS 0.005
CVE-2025-4083
Process isolation bypass using "javascript:" URI links in cross-origin frames
Published 2025-04-29 · Modified
9.1EPSS 0.005
CVE-2026-74961
Side-channel in the Web Audio component
Published 2026-08-18 · Undergoing Analysis
9.1EPSS 0.004
CVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Published 2026-08-18 · Analyzed
9.1EPSS 0.004
CVE-2026-4724
Undefined behavior in the Audio/Video component
Published 2026-03-24 · Modified
9.1EPSS 0.004
CVE-2026-16392
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.1EPSS 0.004
CVE-2026-84639
Uninitialized memory in MIME parsing
Published 2026-09-01 · Analyzed
9.1EPSS 0.003
CVE-2026-16390
Mitigation bypass in the Enterprise Policies component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16370
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16380
Mitigation bypass in the Networking component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16364
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16393
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16359
Incorrect boundary conditions in the Audio/Video: GMP component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-12315
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
9.1EPSS 0.003
CVE-2026-12316
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
9.1EPSS 0.002
CVE-2025-8037
Nameless cookies shadow secure cookies
Published 2025-07-22 · Modified
9.1EPSS 0.002
CVE-2026-12304
Same-origin policy bypass in the Networking: Cookies component
Published 2026-06-16 · Analyzed
9.1EPSS 0.002
CVE-2026-16381
Same-origin policy bypass in the Networking: DNS component
Published 2026-07-21 · Analyzed
9.1EPSS 0.002
CVE-2023-4863
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Published 2023-09-12 · Analyzed
8.8KEVEPSS 1.000
CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Published 2024-05-14 · Modified
8.81 PoCEPSS 0.707
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-28 · Analyzed
8.8KEVEPSS 0.490
CVE-2019-17026
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
Published 2020-03-02 · Analyzed
8.8KEV1 PoCEPSS 0.463
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Published 2019-07-23 · Analyzed
8.8KEV2 PoCEPSS 0.377
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
Published 2016-03-13 · Modified
8.82 PoCEPSS 0.309
CVE-2019-9810
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
Published 2019-04-26 · Modified
8.82 PoCEPSS 0.297
CVE-2022-1802
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
Published 2022-12-22 · Modified
8.8EPSS 0.267
CVE-2022-2200
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Published 2022-12-22 · Modified
8.8EPSS 0.239
CVE-2023-6856
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Published 2023-12-19 · Modified
8.8EPSS 0.206
CVE-2022-1529
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
Published 2022-12-22 · Modified
8.8EPSS 0.171
CVE-2022-26485
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Published 2022-12-22 · Analyzed
8.8KEVEPSS 0.143
CVE-2018-5146
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
Published 2018-06-11 · Modified
8.8EPSS 0.119
CVE-2025-4919
Out-of-bounds access when optimizing linear sums
Published 2025-05-17 · Modified
8.8EPSS 0.086
CVE-2018-5127
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Published 2018-06-11 · Modified
8.8EPSS 0.079
← Prev18 / 48Next →