VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-4728
Spoofing issue in the Privacy: Anti-Tracking component
Published 2026-03-24 · Modified
6.5EPSS 0.003
CVE-2024-8394
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
Published 2024-09-06 · Modified
6.5EPSS 0.003
CVE-2024-11708
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
6.5EPSS 0.003
CVE-2025-1013
Potential opening of private browsing tabs in normal browsing windows
Published 2025-02-04 · Modified
6.5EPSS 0.003
CVE-2026-6763
Mitigation bypass in the File Handling component
Published 2026-04-21 · Analyzed
6.5EPSS 0.003
CVE-2025-10532
Incorrect boundary conditions in the JavaScript: GC component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2026-57963
Chat UI manipulation by injection
Published 2026-07-01 · Analyzed
6.5EPSS 0.003
CVE-2025-4092
Memory safety bugs fixed in Firefox 138 and Thunderbird 138
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2025-10529
Same-origin policy bypass in the Layout component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-10530
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-3031
JIT optimization bug with different stack slot sizes
Published 2025-04-01 · Modified
6.5EPSS 0.003
CVE-2025-4086
Specially crafted filename could be used to obscure download type
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2025-0510
Address of e-mail sender can be spoofed by malicious email
Published 2025-02-04 · Modified
6.5EPSS 0.003
CVE-2026-12302
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-6755
Mitigation bypass in the DOM: postMessage component
Published 2026-04-21 · Analyzed
6.5EPSS 0.002
CVE-2025-11716
Sandboxed iframes allowed links to open in external apps (Android only)
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12309
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
6.5EPSS 0.002
CVE-2025-11711
Some non-writable Object properties could be modified
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12325
Denial-of-service in the Graphics: ImageLib component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-12319
Denial-of-service in the Audio/Video: Playback component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-16403
Spoofing issue in the Address Bar component
Published 2026-07-21 · Analyzed
6.5EPSS 0.002
CVE-2025-14331
Same-origin policy bypass in the Request Handling component
Published 2025-12-09 · Modified
6.5EPSS 0.002
CVE-2025-4088
Cross-site request forgery via storage access API redirects
Published 2025-04-29 · Modified
6.5EPSS 0.002
CVE-2026-8971
Same-origin policy bypass in the Networking: JAR component
Published 2026-05-19 · Analyzed
6.5EPSS 0.002
CVE-2006-2781
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
Published 2006-06-02 · Modified
6.4EPSS 0.033
CVE-2012-4196
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
Published 2012-10-29 · Modified
6.4EPSS 0.033
CVE-2014-1577
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value.
Published 2014-10-15 · Modified
6.4EPSS 0.029
CVE-2006-5462
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Published 2006-11-08 · Modified
6.4EPSS 0.028
CVE-2006-0299
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
Published 2006-02-02 · Modified
6.4EPSS 0.020
CVE-2012-0460
Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.
Published 2012-03-14 · Modified
6.4EPSS 0.020
CVE-2025-3523
User Interface (UI) Misrepresentation of attachment URL
Published 2025-04-15 · Modified
6.4EPSS 0.003
CVE-2024-6600
Memory corruption in WebGL API
Published 2024-07-09 · Modified
6.3EPSS 0.004
CVE-2025-2830
Information Disclosure of /tmp directory listing
Published 2025-04-15 · Modified
6.3EPSS 0.004
CVE-2024-6610
Form validation popups could block exiting full-screen mode
Published 2024-07-09 · Modified
6.3EPSS 0.003
CVE-2026-6757
Invalid pointer in the JavaScript: WebAssembly component
Published 2026-04-21 · Analyzed
6.3EPSS 0.003
CVE-2026-6762
Spoofing issue in the DOM: Core & HTML component
Published 2026-04-21 · Analyzed
6.3EPSS 0.003
CVE-2025-3522
Leak of hashed Window credentials via crafted attachment URL
Published 2025-04-15 · Modified
6.3EPSS 0.003
CVE-2013-1726
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
Published 2013-09-18 · Modified
6.2EPSS 0.003
CVE-2025-10536
Information disclosure in the Networking: Cache component
Published 2025-09-16 · Modified
6.2EPSS 0.002
CVE-2020-6798
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Published 2020-03-02 · Modified
6.1EPSS 0.021
← Prev38 / 48Next →