VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-6761
Privilege escalation in the Networking component
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2026-74950
Privilege escalation in the Downloads API component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2025-8034
Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2025-14329
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2026-8952
Privilege escalation in the Application Update component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2025-14328
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2025-1930
AudioIPC StreamData could trigger a use-after-free in the Browser process
Published 2025-03-04 · Modified
8.8EPSS 0.004
CVE-2026-12289
Privilege escalation in the Graphics: WebRender component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2025-1014
Certificate length was not properly checked
Published 2025-02-04 · Modified
8.8EPSS 0.004
CVE-2026-12291
Use-after-free in the Networking: HTTP component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2025-8035
Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2026-84131
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-09-01 · Analyzed
8.8EPSS 0.003
CVE-2025-11714
Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2025-10537
Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143
Published 2025-09-16 · Modified
8.8EPSS 0.003
CVE-2025-11715
Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2025-8040
Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.003
CVE-2026-16371
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16372
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16362
Use-after-free in the WebRTC: Audio/Video component
Published 2026-07-21 · Analyzed
8.8EPSS 0.003
CVE-2026-16379
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16365
Privilege escalation in the DOM: Workers component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16366
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16396
Privilege escalation in WebExtensions
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2026-16401
Privilege escalation in the Data Loss Prevention component
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2018-5129
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Published 2018-06-11 · Modified
8.6EPSS 0.030
CVE-2023-4576
Integer Overflow in RecordedSourceSurfaceCreation
Published 2023-09-11 · Modified
8.6EPSS 0.008
CVE-2024-5696
By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
8.6EPSS 0.008
CVE-2022-46872
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Published 2022-12-22 · Modified
8.6EPSS 0.008
CVE-2026-8958
Information disclosure, sandbox escape in the Security: Process Sandboxing component
Published 2026-05-19 · Analyzed
8.6EPSS 0.004
CVE-2024-2608
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Published 2024-03-19 · Analyzed
8.4EPSS 0.004
CVE-2019-9811
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Published 2019-07-23 · Modified
8.3EPSS 0.026
CVE-2019-9818
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Published 2019-07-23 · Modified
8.3EPSS 0.010
CVE-2026-4371
Out of bounds read in IMAP parsing
Published 2026-03-24 · Modified
8.2EPSS 0.006
CVE-2025-1943
Memory safety bugs fixed in Firefox 136 and Thunderbird 136
Published 2025-03-04 · Modified
8.2EPSS 0.004
CVE-2024-6606
Out-of-bounds read in clipboard component
Published 2024-07-09 · Analyzed
8.2EPSS 0.004
CVE-2020-6820
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Published 2020-04-24 · Analyzed
8.1KEVEPSS 0.071
CVE-2018-5178
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
Published 2018-06-11 · Modified
8.1EPSS 0.050
CVE-2025-6436
Memory safety bugs fixed in Firefox 140 and Thunderbird 140
Published 2025-06-24 · Modified
8.1EPSS 0.043
CVE-2020-6819
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Published 2020-04-24 · Analyzed
8.1KEVEPSS 0.030
CVE-2016-1526
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
Published 2016-02-13 · Modified
8.1EPSS 0.023
← Prev24 / 48Next →