VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2024-11691
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
Published 2024-11-26 · Analyzed
8.8EPSS 0.007
CVE-2022-28289
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
Published 2022-12-22 · Modified
8.8EPSS 0.007
CVE-2022-38473
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
Published 2022-12-22 · Modified
8.8EPSS 0.007
CVE-2024-11699
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Published 2024-11-26 · Modified
8.8EPSS 0.007
CVE-2023-25739
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
8.8EPSS 0.007
CVE-2023-25729
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
8.8EPSS 0.007
CVE-2023-25746
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
8.8EPSS 0.007
CVE-2026-0880
Sandbox escape due to integer overflow in the Graphics component
Published 2026-01-13 · Modified
8.8EPSS 0.007
CVE-2022-31739
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
8.8EPSS 0.007
CVE-2022-31741
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
8.8EPSS 0.007
CVE-2025-2817
Privilege escalation in Thunderbird Updater
Published 2025-04-29 · Modified
8.8EPSS 0.007
CVE-2022-31740
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
8.8EPSS 0.007
CVE-2024-7520
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
Published 2024-08-06 · Modified
8.8EPSS 0.006
CVE-2023-3600
Use-after-free in workers
Published 2023-07-12 · Modified
8.8EPSS 0.006
CVE-2024-0751
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Published 2024-01-23 · Modified
8.8EPSS 0.006
CVE-2026-2447
Heap buffer overflow in libvpx
Published 2026-02-16 · Modified
8.8EPSS 0.006
CVE-2024-7527
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Modified
8.8EPSS 0.006
CVE-2026-2769
Use-after-free in the Storage: IndexedDB component
Published 2026-02-24 · Modified
8.8EPSS 0.006
CVE-2024-4770
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Published 2024-05-14 · Analyzed
8.8EPSS 0.006
CVE-2026-6750
Privilege escalation in the Graphics: WebRender component
Published 2026-04-21 · Modified
8.8EPSS 0.006
CVE-2026-8975
Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.006
CVE-2024-9396
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Analyzed
8.8EPSS 0.006
CVE-2024-6609
Memory corruption in NSS
Published 2024-07-09 · Modified
8.8EPSS 0.006
CVE-2024-6607
Leaving pointerlock by pressing the escape key could be prevented
Published 2024-07-09 · Analyzed
8.8EPSS 0.006
CVE-2022-22763
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
Published 2022-12-22 · Modified
8.8EPSS 0.006
CVE-2024-4777
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Published 2024-05-14 · Modified
8.8EPSS 0.005
CVE-2024-9400
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Analyzed
8.8EPSS 0.005
CVE-2026-74946
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74941
Privilege escalation in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74969
Use-after-free in the Layout: Text and Fonts component
Published 2026-08-18 · Modified
8.8EPSS 0.005
CVE-2026-0882
Use-after-free in the IPC component
Published 2026-01-13 · Modified
8.8EPSS 0.005
CVE-2026-7322
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Published 2026-04-28 · Modified
8.8EPSS 0.005
CVE-2026-74949
Privilege escalation due to use-after-free in the Graphics: Canvas2D component
Published 2026-08-18 · Modified
8.8EPSS 0.005
CVE-2026-2798
Use-after-free in the DOM: Core & HTML component
Published 2026-02-24 · Modified
8.8EPSS 0.005
CVE-2026-8973
Memory safety bugs fixed in Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.005
CVE-2026-74935
Privilege escalation in the DOM: Networking component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74942
Privilege escalation in the Remote Settings Client component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74939
Privilege escalation in the DOM: Navigation component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74947
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-8974
Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.004
← Prev21 / 44Next →