VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-8962
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-12290
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2026-8969
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-74978
Clickjacking issue in the Widget component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-9184
Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
8.1EPSS 0.004
CVE-2026-12326
Memory safety bugs fixed in Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2025-11713
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-10-14 · Modified
8.1EPSS 0.004
CVE-2025-10534
Spoofing issue in the Site Permissions component
Published 2025-09-16 · Modified
8.1EPSS 0.004
CVE-2025-8030
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8029
javascript: URLs executed on object and embed tags
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8032
XSLT documents could bypass CSP
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8039
Search terms persisted in URL bar
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-9180
Same-origin policy bypass in the Graphics: Canvas2D component
Published 2025-08-19 · Modified
8.1EPSS 0.002
CVE-2026-74962
Site isolation issue in the Networking: Cookies component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-74960
Site isolation issue in the WebExtensions component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-74981
Site isolation issue in the Audio/Video: Web Codecs component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-0878
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-01-13 · Modified
8.0EPSS 0.005
CVE-2025-14322
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2025-12-09 · Modified
8.0EPSS 0.003
CVE-2008-4068
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.
Published 2008-09-24 · Modified
7.8EPSS 0.042
CVE-2017-5419
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the operating system. This is a denial of service (DOS) attack. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Published 2018-06-11 · Modified
7.8EPSS 0.023
CVE-2017-7755
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
7.8EPSS 0.014
CVE-2017-7814
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Published 2018-06-11 · Modified
7.8EPSS 0.012
CVE-2020-12393
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Published 2020-05-26 · Modified
7.8EPSS 0.010
CVE-2018-12379
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Published 2018-10-18 · Modified
7.8EPSS 0.004
CVE-2020-15657
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Published 2020-08-10 · Modified
7.8EPSS 0.004
CVE-2019-17009
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Published 2020-01-08 · Modified
7.8EPSS 0.003
CVE-2021-29949
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1.
Published 2021-06-24 · Modified
7.8EPSS 0.003
CVE-2024-3857
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-04-16 · Analyzed
7.8EPSS 0.002
CVE-2023-37208
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Published 2023-07-05 · Modified
7.8EPSS 0.002
CVE-2022-3155
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
Published 2022-12-22 · Modified
7.8EPSS 0.002
CVE-2026-6776
Incorrect boundary conditions in the WebRTC: Networking component
Published 2026-04-21 · Analyzed
7.8EPSS 0.002
CVE-2025-0241
Memory corruption when using JavaScript Text Segmentation
Published 2025-01-07 · Modified
7.7EPSS 0.007
CVE-2025-3033
Opening local .url files could lead to another file being opened
Published 2025-04-01 · Modified
7.7EPSS 0.002
CVE-2006-1727
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
Published 2006-04-14 · Modified
7.6EPSS 0.064
CVE-2011-2373
Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.
Published 2011-06-30 · Modified
7.6EPSS 0.050
CVE-2025-1933
JIT corruption of WASM i32 return values on 64-bit CPUs
Published 2025-03-04 · Modified
7.6EPSS 0.003
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
Published 2018-06-11 · Analyzed
7.5KEV2 PoCEPSS 0.874
CVE-2011-3658
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
Published 2011-12-21 · Modified
7.51 PoCEPSS 0.696
CVE-2014-1568
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
Published 2014-09-25 · Modified
7.5EPSS 0.167
CVE-2016-9066
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Published 2018-06-11 · Modified
7.5EPSS 0.123
← Prev26 / 48Next →