VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2026-6786
Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2024-10462
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.005
CVE-2024-10465
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.005
CVE-2026-6785
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2024-11702
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
7.5EPSS 0.005
CVE-2024-9394
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-6759
Use-after-free in the Widget: Cocoa component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-6781
Denial-of-service in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-6780
Denial-of-service in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-4726
Denial-of-service in the XML component
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-4727
Denial-of-service in the Libraries component in NSS
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-6758
Use-after-free in the JavaScript: WebAssembly component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2024-9399
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-7323
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.005
CVE-2026-6752
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6751
Uninitialized memory in the Audio/Video: Web Codecs component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6753
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6772
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-74958
Information disclosure in the WebRTC component
Published 2026-08-18 · Analyzed
7.5EPSS 0.005
CVE-2025-5262
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
Published 2025-05-27 · Analyzed
7.5EPSS 0.004
CVE-2026-8947
Use-after-free in the DOM: Bindings (WebIDL) component
Published 2026-05-19 · Modified
7.5EPSS 0.004
CVE-2026-2803
Information disclosure, mitigation bypass in the Settings UI component
Published 2026-02-24 · Modified
7.5EPSS 0.004
CVE-2026-8090
Use-after-free in the DOM: Networking component
Published 2026-05-07 · Modified
7.5EPSS 0.004
CVE-2026-84132
Information disclosure in the Networking: HTTP component
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-84130
Information disclosure in the Graphics: WebGPU component
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-74966
Information disclosure in the Form Autofill component
Published 2026-08-18 · Analyzed
7.5EPSS 0.004
CVE-2026-74954
Information disclosure due to side-channel in the Storage: Cache API component
Published 2026-08-18 · Analyzed
7.5EPSS 0.004
CVE-2026-8954
Incorrect boundary conditions, integer overflow in the Audio/Video component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-6766
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2026-84144
Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-8967
Information disclosure in the Graphics: WebGPU component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-6782
Information disclosure in the IP Protection component
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2026-8965
Information disclosure in the DOM: Security component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8966
Information disclosure in the IP Protection component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-84642
Allowed UNC hostnames for attachments interpreted as a regular expression
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-6784
Memory safety bugs fixed in Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.004
CVE-2026-2783
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
7.5EPSS 0.004
CVE-2026-8963
Spoofing issue in the Web Speech component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8960
Spoofing issue in WebExtensions
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2024-9393
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.004
← Prev28 / 44Next →