VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2023-25752
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Published 2023-06-02 · Modified
6.5EPSS 0.006
CVE-2023-23599
Malicious command could be hidden in devtools output on Windows
Published 2023-06-02 · Modified
6.5EPSS 0.006
CVE-2023-23602
Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers
Published 2023-06-02 · Modified
6.5EPSS 0.006
CVE-2024-0747
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Published 2024-01-23 · Modified
6.5EPSS 0.006
CVE-2021-23998
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Published 2021-06-24 · Modified
6.5EPSS 0.006
CVE-2022-31742
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
6.5EPSS 0.006
CVE-2021-38497
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Published 2021-11-03 · Modified
6.5EPSS 0.006
CVE-2023-29545
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Published 2023-06-19 · Modified
6.5EPSS 0.006
CVE-2022-31738
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
6.5EPSS 0.006
CVE-2025-5986
Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links
Published 2025-06-11 · Modified
6.5EPSS 0.006
CVE-2022-31744
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
Published 2022-12-22 · Modified
6.5EPSS 0.006
CVE-2022-45420
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Published 2022-12-22 · Modified
6.5EPSS 0.006
CVE-2024-7518
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
Published 2024-08-06 · Modified
6.5EPSS 0.005
CVE-2023-0616
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8.
Published 2023-06-02 · Modified
6.5EPSS 0.005
CVE-2024-11706
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
6.5EPSS 0.005
CVE-2025-1934
Unexpected GC during RegExp bailout processing
Published 2025-03-04 · Modified
6.5EPSS 0.005
CVE-2026-74948
Information disclosure in the Graphics component
Published 2026-08-18 · Analyzed
6.5EPSS 0.004
CVE-2026-74945
Information disclosure in the Graphics: Text component
Published 2026-08-18 · Analyzed
6.5EPSS 0.004
CVE-2021-4126
When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression that the additional contents were also covered by the digital signature. Starting with Thunderbird version 91.4.1, only the signature that belongs to the top level MIME part will be considered for the displayed status. This vulnerability affects Thunderbird < 91.4.1.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2022-29913
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2026-74976
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-08-18 · Analyzed
6.5EPSS 0.004
CVE-2021-23993
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.
Published 2021-06-24 · Modified
6.5EPSS 0.004
CVE-2023-4580
Push notifications saved to disk unencrypted
Published 2023-09-11 · Modified
6.5EPSS 0.004
CVE-2026-0885
Use-after-free in the JavaScript: GC component
Published 2026-01-13 · Modified
6.5EPSS 0.004
CVE-2022-2226
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2026-6770
Other issue in the Storage: IndexedDB component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2026-6764
Incorrect boundary conditions in the DOM: Device Interfaces component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2022-1834
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email message with the attacker's digital signature, that was shown with an arbitrary sender email address chosen by the attacker. If the sender name started with a false email address, followed by many Braille space characters, the attacker's email address was not visible. Because Thunderbird compared the invisible sender address with the signature's email address, if the signing key or certificate was accepted by Thunderbird, the email was shown as having a valid digital signature. This vulnerability affects Thunderbird < 91.10.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2025-8027
JavaScript engine only wrote partial return value to stack
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2025-8033
Incorrect JavaScript state machine for generators
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2023-0430
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird < 102.7.1.
Published 2023-06-02 · Modified
6.5EPSS 0.004
CVE-2023-0547
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.
Published 2023-06-02 · Modified
6.5EPSS 0.004
CVE-2025-3932
Tracking Links in Attachments Bypassed Remote Content Blocking
Published 2025-05-14 · Modified
6.5EPSS 0.004
CVE-2022-38472
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2025-9181
Uninitialized memory in the JavaScript Engine component
Published 2025-08-19 · Modified
6.5EPSS 0.004
CVE-2026-3889
Spoofing issue in Thunderbird
Published 2026-03-24 · Modified
6.5EPSS 0.004
CVE-2023-23601
URL being dragged from cross-origin iframe into same tab triggers navigation
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2023-28164
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2026-8961
Spoofing issue in the Form Autofill component
Published 2026-05-19 · Analyzed
6.5EPSS 0.003
CVE-2025-1938
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
6.5EPSS 0.003
← Prev37 / 48Next →