VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2004-0765
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.
Published 2004-08-03 · Modified
7.5EPSS 0.010
CVE-2020-12398
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.
Published 2020-07-09 · Modified
7.5EPSS 0.010
CVE-2023-32214
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
Published 2023-06-19 · Modified
7.5EPSS 0.009
CVE-2024-5702
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
7.5EPSS 0.009
CVE-2021-29950
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.
Published 2021-06-24 · Modified
7.5EPSS 0.009
CVE-2022-38476
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
Published 2022-12-22 · Modified
7.5EPSS 0.008
CVE-2024-10466
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.008
CVE-2026-4694
Incorrect boundary conditions, integer overflow in the Graphics component
Published 2026-03-24 · Modified
7.5EPSS 0.008
CVE-2022-22737
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-1546
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Analyzed
7.5EPSS 0.007
CVE-2022-36319
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-10463
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.007
CVE-2023-4583
Browsing Context potentially not cleared when closing Private Window
Published 2023-09-11 · Modified
7.5EPSS 0.007
CVE-2024-1936
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird < 115.8.1.
Published 2024-03-04 · Analyzed
7.5EPSS 0.007
CVE-2024-1552
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Modified
7.5EPSS 0.007
CVE-2023-3417
File Extension Spoofing using the Text Direction Override Character
Published 2023-07-24 · Modified
7.5EPSS 0.007
CVE-2022-26387
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-7652
Type Confusion in Async Generators in Javascript Engine
Published 2024-09-06 · Analyzed
7.5EPSS 0.007
CVE-2022-22741
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-3852
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-04-16 · Analyzed
7.5EPSS 0.006
CVE-2026-0889
Denial-of-service in the DOM: Service Workers component
Published 2026-01-13 · Modified
7.5EPSS 0.006
CVE-2024-10458
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
CVE-2026-8946
Incorrect boundary conditions in the Audio/Video: Web Codecs component
Published 2026-05-19 · Modified
7.5EPSS 0.006
CVE-2026-6749
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-7320
Information disclosure due to incorrect boundary conditions in the Audio/Video component
Published 2026-04-28 · Modified
7.5EPSS 0.006
CVE-2024-10464
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
CVE-2026-74977
Integer overflow in the Graphics component
Published 2026-08-18 · Analyzed
7.5EPSS 0.006
CVE-2026-8949
Integer overflow in the Widget: Win32 component
Published 2026-05-19 · Analyzed
7.5EPSS 0.006
CVE-2024-10459
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
CVE-2026-6773
Denial-of-service due to integer overflow in the Graphics: WebGPU component
Published 2026-04-21 · Analyzed
7.5EPSS 0.006
CVE-2024-7526
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Modified
7.5EPSS 0.006
CVE-2026-6746
Use-after-free in the DOM: Core & HTML component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-6747
Use-after-free in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-6754
Use-after-free in the JavaScript Engine component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2025-1937
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
7.5EPSS 0.006
CVE-2024-6604
Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13
Published 2024-07-09 · Analyzed
7.5EPSS 0.005
CVE-2025-1931
Use-after-free in WebTransportChild
Published 2025-03-04 · Modified
7.5EPSS 0.005
CVE-2026-2801
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
7.5EPSS 0.005
CVE-2026-74982
Denial-of-service in the Widget component
Published 2026-08-18 · Analyzed
7.5EPSS 0.005
CVE-2026-8968
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
Published 2026-05-19 · Analyzed
7.5EPSS 0.005
← Prev27 / 44Next →