VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2024-6615
Memory safety bugs fixed in Firefox 128 and Thunderbird 128
Published 2024-07-09 · Analyzed
8.8EPSS 0.004
CVE-2026-74965
Privilege escalation in the Shell Integration component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-74953
Privilege escalation in the Networking: Cookies component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-84128
Privilege escalation in the WebDriver BiDi component
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2026-8972
Privilege escalation in the WebRTC: Audio/Video component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-74937
Use-after-free in the JavaScript: GC component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-84123
Privilege escalation due to use-after-free in the Graphics: WebGPU component
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2026-8957
Privilege escalation in the Enterprise Policies component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-6769
Privilege escalation in the Debugger component
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2026-6761
Privilege escalation in the Networking component
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2025-14323
Privilege escalation in the DOM: Notifications component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2026-8955
Privilege escalation in the DOM: Workers component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-74952
Privilege escalation in the Application Update component
Published 2026-08-18 · Modified
8.8EPSS 0.004
CVE-2026-74950
Privilege escalation in the Downloads API component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-8970
Privilege escalation in the Security component
Published 2026-05-19 · Analyzed
8.8EPSS 0.004
CVE-2026-74955
Privilege escalation in the Request Handling component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2025-8034
Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2025-14328
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2025-14329
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2026-8952
Privilege escalation in the Application Update component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2025-1930
AudioIPC StreamData could trigger a use-after-free in the Browser process
Published 2025-03-04 · Modified
8.8EPSS 0.004
CVE-2026-12289
Privilege escalation in the Graphics: WebRender component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2025-1014
Certificate length was not properly checked
Published 2025-02-04 · Modified
8.8EPSS 0.004
CVE-2026-12291
Use-after-free in the Networking: HTTP component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2025-8035
Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2025-11714
Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2026-84131
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-09-01 · Analyzed
8.8EPSS 0.003
CVE-2025-10537
Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143
Published 2025-09-16 · Modified
8.8EPSS 0.003
CVE-2025-11715
Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2025-8040
Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.003
CVE-2026-16371
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16372
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16362
Use-after-free in the WebRTC: Audio/Video component
Published 2026-07-21 · Analyzed
8.8EPSS 0.003
CVE-2026-16379
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16365
Privilege escalation in the DOM: Workers component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16366
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16396
Privilege escalation in WebExtensions
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2026-16401
Privilege escalation in the Data Loss Prevention component
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2018-5129
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Published 2018-06-11 · Modified
8.6EPSS 0.030
CVE-2023-4576
Integer Overflow in RecordedSourceSurfaceCreation
Published 2023-09-11 · Modified
8.6EPSS 0.008
← Prev22 / 44Next →