VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-8954
Incorrect boundary conditions, integer overflow in the Audio/Video component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-6766
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2026-8965
Information disclosure in the DOM: Security component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-6782
Information disclosure in the IP Protection component
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2026-8966
Information disclosure in the IP Protection component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-84144
Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-8967
Information disclosure in the Graphics: WebGPU component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-84642
Allowed UNC hostnames for attachments interpreted as a regular expression
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-6784
Memory safety bugs fixed in Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.004
CVE-2026-2783
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
7.5EPSS 0.004
CVE-2026-8963
Spoofing issue in the Web Speech component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8960
Spoofing issue in WebExtensions
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2024-9393
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.004
CVE-2026-8964
Spoofing issue in the Popup Blocker component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2025-3875
Sender Spoofing via Malformed From Header in Thunderbird
Published 2025-05-14 · Modified
7.5EPSS 0.004
CVE-2025-14327
Spoofing issue in the Downloads Panel component
Published 2025-12-09 · Modified
7.5EPSS 0.004
CVE-2025-9182
Denial-of-service due to out-of-memory in the Graphics: WebRender component
Published 2025-08-19 · Modified
7.5EPSS 0.004
CVE-2026-12305
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.004
CVE-2026-84138
Denial-of-service in the PDF Viewer component
Published 2026-09-01 · Modified
7.5EPSS 0.004
CVE-2026-84145
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-7324
Memory safety bugs fixed in Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.004
CVE-2026-16376
Denial-of-service in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.004
CVE-2026-16354
Information disclosure in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16374
Information disclosure in the Framework component in DevTools
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16391
Information disclosure in the Storage: IndexedDB component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12329
Memory safety bug fixed in Thunderbird ESR 140.12
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16385
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16384
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16386
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16378
Other issue in the DOM: Copy & Paste and Drag & Drop component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12298
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12299
JIT miscompilation in the DOM: Core & HTML component
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12317
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16409
Invalid pointer in the Security: PSM component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-14899
Off-by-one out of bounds read in MIME header parser for forwarding
Published 2026-07-22 · Analyzed
7.5EPSS 0.003
CVE-2026-84641
Information disclosure due to malicious IMAP server response
Published 2026-09-01 · Analyzed
7.5EPSS 0.003
CVE-2026-84640
One byte overflow read in mail parser
Published 2026-09-01 · Analyzed
7.5EPSS 0.003
CVE-2026-12312
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12314
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12310
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
← Prev31 / 48Next →