VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2023-6206
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Published 2023-11-21 · Modified
5.4EPSS 0.006
CVE-2022-28286
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
Published 2022-12-22 · Modified
5.4EPSS 0.006
CVE-2023-25730
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
5.4EPSS 0.005
CVE-2024-11695
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Published 2024-11-26 · Modified
5.4EPSS 0.004
CVE-2022-1197
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability affects Thunderbird < 91.8.
Published 2022-12-22 · Modified
5.4EPSS 0.004
CVE-2024-11696
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed. Signature validation in this context is used to ensure that third-party applications on the user's computer have not tampered with the user's extensions, limiting the impact of this issue. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Published 2024-11-26 · Modified
5.4EPSS 0.003
CVE-2024-10460
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
5.4EPSS 0.003
CVE-2026-0890
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component
Published 2026-01-13 · Modified
5.4EPSS 0.003
CVE-2026-2804
Use-after-free in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
5.4EPSS 0.003
CVE-2026-84118
Use-after-free in the JavaScript: GC component
Published 2026-09-01 · Analyzed
5.4EPSS 0.003
CVE-2026-84125
Use-after-free in the DOM: Core & HTML component
Published 2026-09-01 · Analyzed
5.4EPSS 0.003
CVE-2025-10531
Mitigation bypass in the Web Compatibility: Tooling component
Published 2025-09-16 · Modified
5.4EPSS 0.003
CVE-2026-6774
Mitigation bypass in the DOM: Security component
Published 2026-04-21 · Analyzed
5.4EPSS 0.003
CVE-2026-84120
Use-after-free in the Audio/Video component
Published 2026-09-01 · Analyzed
5.4EPSS 0.002
CVE-2026-84122
Use-after-free in the Audio/Video component
Published 2026-09-01 · Analyzed
5.4EPSS 0.002
CVE-2026-12322
Clickjacking issue in the Widget: Gtk component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-84124
Use-after-free in the DOM: Core & HTML component
Published 2026-09-01 · Analyzed
5.4EPSS 0.002
CVE-2026-74974
Same-origin policy bypass in the Graphics: ImageLib component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-12323
Spoofing issue in the DOM: Core & HTML component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-74963
Same-origin policy bypass in the Networking: Cookies component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-74967
Same-origin policy bypass in the Audio/Video: Playback component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-12330
Incorrect boundary conditions in the Internationalization component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-12321
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-74970
Site isolation issue in the Graphics component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-74968
Site isolation issue in the Graphics: WebRender component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2019-7317
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Published 2019-02-04 · Modified
5.3EPSS 0.094
CVE-2017-5462
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
5.3EPSS 0.026
CVE-2017-5405
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Published 2018-06-11 · Modified
5.3EPSS 0.026
CVE-2017-5408
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Published 2018-06-11 · Modified
5.3EPSS 0.026
CVE-2017-5383
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Published 2018-06-11 · Modified
5.3EPSS 0.025
CVE-2018-5117
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Published 2018-06-11 · Modified
5.3EPSS 0.024
CVE-2018-5168
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Published 2018-06-11 · Modified
5.3EPSS 0.024
CVE-2019-11717
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Published 2019-07-23 · Modified
5.3EPSS 0.021
CVE-2017-7764
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
5.3EPSS 0.020
CVE-2017-7791
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Published 2018-06-11 · Modified
5.3EPSS 0.018
CVE-2017-7829
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
Published 2018-06-11 · Modified
5.3EPSS 0.018
CVE-2017-7848
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
Published 2018-06-11 · Modified
5.3EPSS 0.018
CVE-2018-18509
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an email message with arbitrary content. This vulnerability affects Thunderbird < 60.5.1.
Published 2019-04-26 · Modified
5.3EPSS 0.017
CVE-2017-7825
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Published 2018-06-11 · Modified
5.3EPSS 0.016
CVE-2020-6812
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Published 2020-03-25 · Modified
5.3EPSS 0.016
← Prev38 / 44Next →