VendorsMozillathunderbirdany version
Vulnerabilities

Mozilla Thunderbird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1742CVEs
CVE-2017-5426
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Published 2018-06-11 · Modified
5.3EPSS 0.014
CVE-2019-11698
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Published 2019-07-23 · Modified
5.3EPSS 0.014
CVE-2020-12405
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Published 2020-07-09 · Modified
5.3EPSS 0.014
CVE-2019-9801
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Published 2019-04-26 · Modified
5.3EPSS 0.013
CVE-2017-5418
An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set patterns. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Published 2018-06-11 · Modified
5.3EPSS 0.013
CVE-2017-7763
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
5.3EPSS 0.011
CVE-2017-7782
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Published 2018-06-11 · Modified
5.3EPSS 0.011
CVE-2025-0238
Use-after-free when breaking lines in text
Published 2025-01-07 · Modified
5.3EPSS 0.008
CVE-2019-9817
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Published 2019-07-23 · Modified
5.3EPSS 0.008
CVE-2023-6857
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Published 2023-12-19 · Modified
5.3EPSS 0.007
CVE-2024-9398
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
5.3EPSS 0.006
CVE-2022-36318
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
Published 2022-12-22 · Modified
5.3EPSS 0.005
CVE-2024-6612
CSP violation leakage when using devtools
Published 2024-07-09 · Analyzed
5.3EPSS 0.005
CVE-2026-0886
Incorrect boundary conditions in the Graphics component
Published 2026-01-13 · Modified
5.3EPSS 0.005
CVE-2026-0883
Information disclosure in the Networking component
Published 2026-01-13 · Modified
5.3EPSS 0.005
CVE-2026-6778
Invalid pointer in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
5.3EPSS 0.004
CVE-2026-6767
Other issue in the Libraries component in NSS
Published 2026-04-21 · Analyzed
5.3EPSS 0.004
CVE-2026-6783
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
5.3EPSS 0.004
CVE-2026-6765
Information disclosure in the Form Autofill component
Published 2026-04-21 · Analyzed
5.3EPSS 0.004
CVE-2026-0888
Information disclosure in the XML component
Published 2026-01-13 · Modified
5.3EPSS 0.004
CVE-2026-6775
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Analyzed
5.3EPSS 0.003
CVE-2026-6779
Other issue in the JavaScript Engine component
Published 2026-04-21 · Analyzed
5.3EPSS 0.003
CVE-2026-57962
Denial-of-service via malicious LDAP address-book server
Published 2026-07-01 · Analyzed
5.3EPSS 0.003
CVE-2025-4090
Leaked library paths in Thunderbird for Android
Published 2025-04-29 · Modified
5.3EPSS 0.003
CVE-2024-11159
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
Published 2024-11-13 · Modified
5.3EPSS 0.003
CVE-2026-12306
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12307
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12308
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12300
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12301
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-6777
Other issue in the Networking: DNS component
Published 2026-04-21 · Analyzed
5.3EPSS 0.002
CVE-2025-26695
Downloading of OpenPGP keys from WKD used incorrect padding
Published 2025-03-10 · Modified
5.3EPSS 0.002
CVE-2015-0813
Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.
Published 2015-04-01 · Modified
5.1EPSS 0.053
CVE-2010-0179
Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
Published 2010-04-05 · Modified
5.1EPSS 0.033
CVE-2025-0243
Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
Published 2025-01-07 · Modified
5.1EPSS 0.003
CVE-2025-4089
Potential local code execution in "copy as cURL" command
Published 2025-04-29 · Modified
5.1EPSS 0.002
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
Published 2015-04-01 · Modified
5.01 PoCEPSS 0.669
CVE-2013-6629
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
Published 2013-11-15 · Modified
5.0EPSS 0.097
CVE-2009-2535
Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
Published 2009-07-20 · Modified
5.01 PoCEPSS 0.094
CVE-2013-0791
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.
Published 2013-04-03 · Modified
5.0EPSS 0.052
← Prev39 / 44Next →