VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2017-7807
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Published 2018-06-11 · Modified
8.1EPSS 0.021
CVE-2019-9815
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update to macOS 10.14.5 in order to take advantage of this change.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Published 2019-07-23 · Modified
8.1EPSS 0.018
CVE-2020-12387
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Published 2020-05-26 · Modified
8.1EPSS 0.014
CVE-2021-29986
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Published 2021-08-17 · Modified
8.1EPSS 0.013
CVE-2021-23981
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
Published 2021-03-31 · Modified
8.1EPSS 0.011
CVE-2024-2607
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Published 2024-03-19 · Analyzed
8.1EPSS 0.011
CVE-2024-5688
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
8.1EPSS 0.011
CVE-2024-2612
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Published 2024-03-19 · Analyzed
8.1EPSS 0.010
CVE-2021-29991
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
Published 2021-11-03 · Modified
8.1EPSS 0.009
CVE-2024-1553
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Analyzed
8.1EPSS 0.009
CVE-2024-3864
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-04-16 · Analyzed
8.1EPSS 0.009
CVE-2023-25734
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
8.1EPSS 0.008
CVE-2022-3033
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attributes in the email, it was possible to execute JavaScript code included in the message in the context of the message compose document. The JavaScript code was able to perform actions including, but probably not limited to, read and modify the contents of the message compose document, including the quoted original message, which could potentially contain the decrypted plaintext of encrypted data in the crafted email. The contents could then be transmitted to the network, either to the URL specified in the META refresh tag, or to a different URL, as the JavaScript code could modify the URL specified in the document. This bug doesn't affect users who have changed the default Message Body display setting to 'simple html' or 'plain text'. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Published 2022-12-22 · Modified
8.1EPSS 0.008
CVE-2026-8092
Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2
Published 2026-05-07 · Modified
8.1EPSS 0.005
CVE-2022-45414
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. These issues could have given an attacker additional capabilities when targetting releases that did not yet have a fix for CVE-2022-3033 which was reported around three months ago. This vulnerability affects Thunderbird < 102.5.1.
Published 2022-12-22 · Modified
8.1EPSS 0.005
CVE-2024-7529
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
8.1EPSS 0.005
CVE-2025-4091
Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10
Published 2025-04-29 · Modified
8.1EPSS 0.005
CVE-2025-3030
Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9
Published 2025-04-01 · Modified
8.1EPSS 0.005
CVE-2026-12292
Incorrect boundary conditions in the Web Audio component
Published 2026-06-16 · Modified
8.1EPSS 0.005
CVE-2025-5268
Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11
Published 2025-05-27 · Modified
8.1EPSS 0.005
CVE-2025-4093
Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10
Published 2025-04-29 · Modified
8.1EPSS 0.005
CVE-2026-0891
Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
Published 2026-01-13 · Modified
8.1EPSS 0.005
CVE-2026-0877
Mitigation bypass in the DOM: Security component
Published 2026-01-13 · Modified
8.1EPSS 0.005
CVE-2024-11700
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
8.1EPSS 0.005
CVE-2026-12328
Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.005
CVE-2025-9185
Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
8.1EPSS 0.005
CVE-2025-5269
Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11
Published 2025-05-27 · Modified
8.1EPSS 0.005
CVE-2026-4718
Undefined behavior in the WebRTC: Signaling component
Published 2026-03-24 · Modified
8.1EPSS 0.005
CVE-2025-3034
Memory safety bugs fixed in Firefox 137 and Thunderbird 137
Published 2025-04-01 · Modified
8.1EPSS 0.005
CVE-2025-6435
Save as in Devtools could download files without sanitizing the extension
Published 2025-06-24 · Modified
8.1EPSS 0.005
CVE-2025-14333
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
8.1EPSS 0.004
CVE-2025-3909
JavaScript Execution via Spoofed PDF Attachment and file:/// Link
Published 2025-05-14 · Modified
8.1EPSS 0.004
CVE-2026-74983
Mitigation bypass in the Data Loss Prevention component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2026-74957
Mitigation bypass in the Safe Browsing component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-8036
DNS rebinding circumvents CORS
Published 2025-07-22 · Modified
8.1EPSS 0.004
CVE-2025-1932
Inconsistent comparator in XSLT sorting led to out-of-bounds access
Published 2025-03-04 · Modified
8.1EPSS 0.004
CVE-2026-8093
Memory safety bugs fixed in Firefox 150.0.2
Published 2026-05-07 · Modified
8.1EPSS 0.004
CVE-2022-42927
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Published 2022-12-22 · Modified
8.1EPSS 0.004
CVE-2026-12327
Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Analyzed
8.1EPSS 0.004
CVE-2026-92239
Buffer overrun in IMAP
Published 2026-09-15 · Analyzed
8.1EPSS 0.004
← Prev25 / 48Next →