VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-8949
Integer overflow in the Widget: Win32 component
Published 2026-05-19 · Analyzed
7.5EPSS 0.006
CVE-2024-10459
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
CVE-2026-6773
Denial-of-service due to integer overflow in the Graphics: WebGPU component
Published 2026-04-21 · Analyzed
7.5EPSS 0.006
CVE-2024-7526
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Modified
7.5EPSS 0.006
CVE-2026-6746
Use-after-free in the DOM: Core & HTML component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-6754
Use-after-free in the JavaScript Engine component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-6747
Use-after-free in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2025-1937
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
7.5EPSS 0.006
CVE-2024-6604
Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13
Published 2024-07-09 · Analyzed
7.5EPSS 0.005
CVE-2025-1931
Use-after-free in WebTransportChild
Published 2025-03-04 · Modified
7.5EPSS 0.005
CVE-2026-2801
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
7.5EPSS 0.005
CVE-2026-74982
Denial-of-service in the Widget component
Published 2026-08-18 · Analyzed
7.5EPSS 0.005
CVE-2026-8968
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
Published 2026-05-19 · Analyzed
7.5EPSS 0.005
CVE-2026-6785
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2024-10462
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.005
CVE-2024-10465
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.005
CVE-2026-6786
Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2024-11702
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
7.5EPSS 0.005
CVE-2024-9394
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-6759
Use-after-free in the Widget: Cocoa component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-4726
Denial-of-service in the XML component
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-6780
Denial-of-service in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-4727
Denial-of-service in the Libraries component in NSS
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-6781
Denial-of-service in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-6758
Use-after-free in the JavaScript: WebAssembly component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2024-9399
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-6753
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6751
Uninitialized memory in the Audio/Video: Web Codecs component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-7323
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.005
CVE-2026-6752
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6772
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-74958
Information disclosure in the WebRTC component
Published 2026-08-18 · Analyzed
7.5EPSS 0.005
CVE-2025-5262
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
Published 2025-05-27 · Analyzed
7.5EPSS 0.004
CVE-2026-2803
Information disclosure, mitigation bypass in the Settings UI component
Published 2026-02-24 · Modified
7.5EPSS 0.004
CVE-2026-8947
Use-after-free in the DOM: Bindings (WebIDL) component
Published 2026-05-19 · Modified
7.5EPSS 0.004
CVE-2026-8090
Use-after-free in the DOM: Networking component
Published 2026-05-07 · Modified
7.5EPSS 0.004
CVE-2026-84132
Information disclosure in the Networking: HTTP component
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-74954
Information disclosure due to side-channel in the Storage: Cache API component
Published 2026-08-18 · Analyzed
7.5EPSS 0.004
CVE-2026-84130
Information disclosure in the Graphics: WebGPU component
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-74966
Information disclosure in the Form Autofill component
Published 2026-08-18 · Analyzed
7.5EPSS 0.004
← Prev30 / 48Next →