VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-16400
Information disclosure in the DOM: Security component
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2026-74934
Site isolation issue in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
7.5EPSS 0.002
CVE-2026-16399
Site isolation issue in the DOM: Navigation component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2026-16398
Site isolation issue in the Graphics component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2024-6603
Memory corruption in thread creation
Published 2024-07-09 · Analyzed
7.4EPSS 0.005
CVE-2025-3032
Leaking file descriptors from the fork server
Published 2025-04-01 · Modified
7.4EPSS 0.004
CVE-2024-9403
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
Published 2024-10-01 · Analyzed
7.3EPSS 0.004
CVE-2025-1936
Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
Published 2025-03-04 · Modified
7.3EPSS 0.004
CVE-2025-1018
Fullscreen notification is not displayed when fullscreen is re-requested
Published 2025-02-04 · Modified
7.3EPSS 0.004
CVE-2025-10528
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component
Published 2025-09-16 · Modified
7.3EPSS 0.004
CVE-2025-14325
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2025-3029
URL Bar Spoofing via non-BMP Unicode characters
Published 2025-04-01 · Modified
7.3EPSS 0.003
CVE-2025-5272
Memory safety bugs fixed in Firefox 139 and Thunderbird 139
Published 2025-05-27 · Modified
7.3EPSS 0.003
CVE-2025-14332
Memory safety bugs fixed in Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2026-12318
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-06-16 · Analyzed
7.3EPSS 0.003
CVE-2026-12324
Incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-06-16 · Analyzed
7.3EPSS 0.002
CVE-2013-0799
Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain privileges via crafted arguments.
Published 2013-04-03 · Modified
7.2EPSS 0.004
CVE-2013-1706
Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
Published 2013-08-07 · Modified
7.2EPSS 0.003
CVE-2013-1707
Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
Published 2013-08-07 · Modified
7.2EPSS 0.003
CVE-2011-2980
Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
Published 2011-08-18 · Modified
7.2EPSS 0.003
CVE-2012-1942
The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context.
Published 2012-06-05 · Modified
7.2EPSS 0.003
CVE-2006-6502
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Published 2006-12-20 · Modified
7.1EPSS 0.024
CVE-2009-0776
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
Published 2009-03-05 · Modified
7.1EPSS 0.016
CVE-2021-29964
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Published 2021-06-24 · Modified
7.1EPSS 0.008
CVE-2022-22753
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Published 2022-12-22 · Modified
7.1EPSS 0.006
CVE-2025-4085
Potential information leakage and privilege escalation in UITour actor
Published 2025-04-29 · Modified
7.1EPSS 0.003
CVE-2025-10527
Sandbox escape due to use-after-free in the Graphics: Canvas2D component
Published 2025-09-16 · Modified
7.1EPSS 0.003
CVE-2024-5700
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
7.0EPSS 0.004
CVE-2018-12385
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.
Published 2018-10-18 · Modified
7.0EPSS 0.004
CVE-2025-26696
Crafted email message incorrectly shown as being encrypted
Published 2025-03-10 · Modified
7.0EPSS 0.003
CVE-2013-0797
Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allows local users to gain privileges via a Trojan horse DLL file in an unspecified directory.
Published 2013-04-03 · Modified
6.9EPSS 0.004
CVE-2013-1712
Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update directory or (2) the current working directory.
Published 2013-08-07 · Modified
6.9EPSS 0.004
CVE-2013-1672
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
Published 2013-05-16 · Modified
6.9EPSS 0.003
CVE-2015-0833
Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dll.
Published 2015-02-25 · Modified
6.9EPSS 0.003
CVE-2012-1943
Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.
Published 2012-06-05 · Modified
6.9EPSS 0.003
CVE-2012-3974
Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.
Published 2012-08-29 · Modified
6.9EPSS 0.003
CVE-2010-3182
A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Published 2010-10-21 · Modified
6.9EPSS 0.003
CVE-2010-3181
Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Published 2010-10-21 · Modified
6.9EPSS 0.003
CVE-2007-0009
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
Published 2007-02-26 · Modified
6.8EPSS 0.506
CVE-2006-6500
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows bitmap.
Published 2006-12-20 · Modified
6.8EPSS 0.086
← Prev32 / 48Next →