VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2026-4718
Undefined behavior in the WebRTC: Signaling component
Published 2026-03-24 · Modified
8.1EPSS 0.005
CVE-2025-5269
Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11
Published 2025-05-27 · Modified
8.1EPSS 0.005
CVE-2025-3034
Memory safety bugs fixed in Firefox 137 and Thunderbird 137
Published 2025-04-01 · Modified
8.1EPSS 0.005
CVE-2025-6435
Save as in Devtools could download files without sanitizing the extension
Published 2025-06-24 · Modified
8.1EPSS 0.005
CVE-2025-14333
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
8.1EPSS 0.004
CVE-2025-3909
JavaScript Execution via Spoofed PDF Attachment and file:/// Link
Published 2025-05-14 · Modified
8.1EPSS 0.004
CVE-2026-74983
Mitigation bypass in the Data Loss Prevention component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2026-74957
Mitigation bypass in the Safe Browsing component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-8036
DNS rebinding circumvents CORS
Published 2025-07-22 · Modified
8.1EPSS 0.004
CVE-2025-1932
Inconsistent comparator in XSLT sorting led to out-of-bounds access
Published 2025-03-04 · Modified
8.1EPSS 0.004
CVE-2026-8093
Memory safety bugs fixed in Firefox 150.0.2
Published 2026-05-07 · Modified
8.1EPSS 0.004
CVE-2022-42927
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Published 2022-12-22 · Modified
8.1EPSS 0.004
CVE-2026-12327
Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Analyzed
8.1EPSS 0.004
CVE-2026-92239
Buffer overrun in IMAP
Published 2026-09-15 · Analyzed
8.1EPSS 0.004
CVE-2026-8962
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-12290
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2026-8969
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-74978
Clickjacking issue in the Widget component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-9184
Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
8.1EPSS 0.004
CVE-2026-12326
Memory safety bugs fixed in Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2025-11713
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-10-14 · Modified
8.1EPSS 0.004
CVE-2025-10534
Spoofing issue in the Site Permissions component
Published 2025-09-16 · Modified
8.1EPSS 0.004
CVE-2025-8029
javascript: URLs executed on object and embed tags
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8030
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8032
XSLT documents could bypass CSP
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8039
Search terms persisted in URL bar
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-9180
Same-origin policy bypass in the Graphics: Canvas2D component
Published 2025-08-19 · Modified
8.1EPSS 0.002
CVE-2026-74962
Site isolation issue in the Networking: Cookies component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-74960
Site isolation issue in the WebExtensions component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-74981
Site isolation issue in the Audio/Video: Web Codecs component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-0878
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-01-13 · Modified
8.0EPSS 0.005
CVE-2025-14322
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2025-12-09 · Modified
8.0EPSS 0.003
CVE-2008-4068
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.
Published 2008-09-24 · Modified
7.8EPSS 0.042
CVE-2017-5419
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the operating system. This is a denial of service (DOS) attack. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Published 2018-06-11 · Modified
7.8EPSS 0.023
CVE-2017-7755
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
7.8EPSS 0.014
CVE-2017-7814
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Published 2018-06-11 · Modified
7.8EPSS 0.012
CVE-2020-12393
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Published 2020-05-26 · Modified
7.8EPSS 0.010
CVE-2018-12379
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Published 2018-10-18 · Modified
7.8EPSS 0.004
CVE-2020-15657
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Published 2020-08-10 · Modified
7.8EPSS 0.004
CVE-2019-17009
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Published 2020-01-08 · Modified
7.8EPSS 0.003
← Prev24 / 44Next →