VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2026-8964
Spoofing issue in the Popup Blocker component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2025-3875
Sender Spoofing via Malformed From Header in Thunderbird
Published 2025-05-14 · Modified
7.5EPSS 0.004
CVE-2025-14327
Spoofing issue in the Downloads Panel component
Published 2025-12-09 · Modified
7.5EPSS 0.004
CVE-2025-9182
Denial-of-service due to out-of-memory in the Graphics: WebRender component
Published 2025-08-19 · Modified
7.5EPSS 0.004
CVE-2026-12305
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.004
CVE-2026-84138
Denial-of-service in the PDF Viewer component
Published 2026-09-01 · Modified
7.5EPSS 0.004
CVE-2026-84145
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-7324
Memory safety bugs fixed in Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.004
CVE-2026-16376
Denial-of-service in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.004
CVE-2026-16354
Information disclosure in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16391
Information disclosure in the Storage: IndexedDB component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16374
Information disclosure in the Framework component in DevTools
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12329
Memory safety bug fixed in Thunderbird ESR 140.12
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16384
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16386
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16385
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16378
Other issue in the DOM: Copy & Paste and Drag & Drop component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12298
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12299
JIT miscompilation in the DOM: Core & HTML component
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12317
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16409
Invalid pointer in the Security: PSM component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-14899
Off-by-one out of bounds read in MIME header parser for forwarding
Published 2026-07-22 · Analyzed
7.5EPSS 0.003
CVE-2026-84641
Information disclosure due to malicious IMAP server response
Published 2026-09-01 · Analyzed
7.5EPSS 0.003
CVE-2026-84640
One byte overflow read in mail parser
Published 2026-09-01 · Analyzed
7.5EPSS 0.003
CVE-2026-12312
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12314
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12310
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16400
Information disclosure in the DOM: Security component
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2026-74934
Site isolation issue in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
7.5EPSS 0.002
CVE-2026-16399
Site isolation issue in the DOM: Navigation component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2026-16398
Site isolation issue in the Graphics component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2024-6603
Memory corruption in thread creation
Published 2024-07-09 · Analyzed
7.4EPSS 0.005
CVE-2025-3032
Leaking file descriptors from the fork server
Published 2025-04-01 · Modified
7.4EPSS 0.004
CVE-2024-9403
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
Published 2024-10-01 · Analyzed
7.3EPSS 0.004
CVE-2025-1936
Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
Published 2025-03-04 · Modified
7.3EPSS 0.004
CVE-2025-1018
Fullscreen notification is not displayed when fullscreen is re-requested
Published 2025-02-04 · Modified
7.3EPSS 0.004
CVE-2025-10528
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component
Published 2025-09-16 · Modified
7.3EPSS 0.004
CVE-2025-3029
URL Bar Spoofing via non-BMP Unicode characters
Published 2025-04-01 · Modified
7.3EPSS 0.003
CVE-2025-14325
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2025-5272
Memory safety bugs fixed in Firefox 139 and Thunderbird 139
Published 2025-05-27 · Modified
7.3EPSS 0.003
← Prev29 / 44Next →