VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2022-2226
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2026-6770
Other issue in the Storage: IndexedDB component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2026-6764
Incorrect boundary conditions in the DOM: Device Interfaces component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2022-1834
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email message with the attacker's digital signature, that was shown with an arbitrary sender email address chosen by the attacker. If the sender name started with a false email address, followed by many Braille space characters, the attacker's email address was not visible. Because Thunderbird compared the invisible sender address with the signature's email address, if the signing key or certificate was accepted by Thunderbird, the email was shown as having a valid digital signature. This vulnerability affects Thunderbird < 91.10.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2025-8027
JavaScript engine only wrote partial return value to stack
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2025-8033
Incorrect JavaScript state machine for generators
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2023-0430
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird < 102.7.1.
Published 2023-06-02 · Modified
6.5EPSS 0.004
CVE-2023-0547
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
Published 2023-06-02 · Modified
6.5EPSS 0.004
CVE-2025-3932
Tracking Links in Attachments Bypassed Remote Content Blocking
Published 2025-05-14 · Modified
6.5EPSS 0.004
CVE-2022-38472
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2025-9181
Uninitialized memory in the JavaScript Engine component
Published 2025-08-19 · Modified
6.5EPSS 0.004
CVE-2026-3889
Spoofing issue in Thunderbird
Published 2026-03-24 · Modified
6.5EPSS 0.004
CVE-2023-23601
URL being dragged from cross-origin iframe into same tab triggers navigation
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2023-28164
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2026-8961
Spoofing issue in the Form Autofill component
Published 2026-05-19 · Analyzed
6.5EPSS 0.003
CVE-2025-1938
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
6.5EPSS 0.003
CVE-2026-4728
Spoofing issue in the Privacy: Anti-Tracking component
Published 2026-03-24 · Modified
6.5EPSS 0.003
CVE-2024-8394
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
Published 2024-09-06 · Modified
6.5EPSS 0.003
CVE-2024-11708
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
6.5EPSS 0.003
CVE-2025-1013
Potential opening of private browsing tabs in normal browsing windows
Published 2025-02-04 · Modified
6.5EPSS 0.003
CVE-2026-6763
Mitigation bypass in the File Handling component
Published 2026-04-21 · Analyzed
6.5EPSS 0.003
CVE-2025-10532
Incorrect boundary conditions in the JavaScript: GC component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2026-57963
Chat UI manipulation by injection
Published 2026-07-01 · Analyzed
6.5EPSS 0.003
CVE-2025-4092
Memory safety bugs fixed in Firefox 138 and Thunderbird 138
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2025-10529
Same-origin policy bypass in the Layout component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-10530
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-3031
JIT optimization bug with different stack slot sizes
Published 2025-04-01 · Modified
6.5EPSS 0.003
CVE-2025-4086
Specially crafted filename could be used to obscure download type
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2025-0510
Address of e-mail sender can be spoofed by malicious email
Published 2025-02-04 · Modified
6.5EPSS 0.003
CVE-2026-12302
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-6755
Mitigation bypass in the DOM: postMessage component
Published 2026-04-21 · Analyzed
6.5EPSS 0.002
CVE-2025-11716
Sandboxed iframes allowed links to open in external apps (Android only)
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12309
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
6.5EPSS 0.002
CVE-2025-11711
Some non-writable Object properties could be modified
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12325
Denial-of-service in the Graphics: ImageLib component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-12319
Denial-of-service in the Audio/Video: Playback component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-16403
Spoofing issue in the Address Bar component
Published 2026-07-21 · Analyzed
6.5EPSS 0.002
CVE-2025-14331
Same-origin policy bypass in the Request Handling component
Published 2025-12-09 · Modified
6.5EPSS 0.002
CVE-2025-4088
Cross-site request forgery via storage access API redirects
Published 2025-04-29 · Modified
6.5EPSS 0.002
CVE-2026-8971
Same-origin policy bypass in the Networking: JAR component
Published 2026-05-19 · Analyzed
6.5EPSS 0.002
← Prev35 / 44Next →