VendorsMozillathunderbirdall versions
Vulnerabilities

Mozilla Thunderbird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1919CVEs
CVE-2026-2796
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
9.8EPSS 0.007
CVE-2026-8956
Integer overflow in the Networking: JAR component
Published 2026-05-19 · Analyzed
9.8EPSS 0.006
CVE-2025-1011
A bug in WebAssembly code generation could result in a crash
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2026-84141
Integer overflow in the Graphics: ImageLib component
Published 2026-09-01 · Modified
9.8EPSS 0.006
CVE-2026-8094
Other issue in the WebRTC component
Published 2026-05-07 · Modified
9.8EPSS 0.006
CVE-2026-84637
Calendar invitation attachments could launch local executables
Published 2026-09-01 · Analyzed
9.8EPSS 0.006
CVE-2026-2792
Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2793
Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2024-7521
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.8EPSS 0.006
CVE-2024-9402
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Analyzed
9.8EPSS 0.006
CVE-2026-2757
Incorrect boundary conditions in the WebRTC: Audio/Video component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2759
Incorrect boundary conditions in the Graphics: ImageLib component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2773
Incorrect boundary conditions in the Web Audio component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2771
Undefined behavior in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-0879
Sandbox escape due to incorrect boundary conditions in the Graphics component
Published 2026-01-13 · Modified
9.8EPSS 0.006
CVE-2026-5731
Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.006
CVE-2026-74988
Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-2788
Incorrect boundary conditions in the Audio/Video: GMP component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-74940
Use-after-free in the Graphics: Text component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-74943
Use-after-free in the Graphics: ImageLib component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-2770
Use-after-free in the DOM: Bindings (WebIDL) component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2766
Use-after-free in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2758
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2763
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2764
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2772
Use-after-free in the Audio/Video: Playback component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2767
Use-after-free in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2765
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-8091
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-05-07 · Modified
9.8EPSS 0.006
CVE-2026-6748
Uninitialized memory in the Audio/Video: Web Codecs component
Published 2026-04-21 · Modified
9.8EPSS 0.006
CVE-2026-4720
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.006
CVE-2025-14321
Use-after-free in the WebRTC: Signaling component
Published 2025-12-09 · Modified
9.8EPSS 0.006
CVE-2024-10467
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
9.8EPSS 0.006
CVE-2026-4721
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.006
CVE-2026-74944
Use-after-free in the DOM: Core & HTML component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-74936
Use-after-free in the JavaScript: WebAssembly component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2025-1016
Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2026-5734
Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.006
CVE-2024-8387
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
Published 2024-09-03 · Modified
9.8EPSS 0.006
CVE-2026-2779
Incorrect boundary conditions in the Networking: JAR component
Published 2026-02-24 · Modified
9.8EPSS 0.006
← Prev9 / 48Next →