mozilla / thunderbird
172 known vulnerabilities in mozilla thunderbird.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-9680 | Act now | 23.2% | 9.8 | ● | An attacker was able to achieve code execution in the content process by exploit… |
| CVE-2022-26485 | Act now | 14.3% | 8.8 | ● | Removing an XSLT parameter during processing could have lead to an exploitable u… |
| CVE-2022-26486 | Act now | 2.3% | 9.6 | ● | An unexpected message in the WebGPU IPC framework could lead to a use-after-free… |
| CVE-2020-15670 | Medium | 1.1% | 8.8 | Mozilla developers reported memory safety bugs present in Firefox for Android 79… | |
| CVE-2023-29541 | Medium | 0.7% | 8.8 | Firefox did not properly handle downloads of files ending in <code>.desktop</cod… | |
| CVE-2023-29539 | Medium | 0.7% | 8.8 | When handling the filename directive in the Content-Disposition header, the file… | |
| CVE-2023-29536 | Medium | 0.7% | 8.8 | An attacker could cause the memory manager to incorrectly free a pointer that ad… | |
| CVE-2023-29550 | Medium | 0.7% | 8.8 | Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these b… | |
| CVE-2026-74943 | Medium | 0.6% | 9.8 | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed… | |
| CVE-2026-16389 | Medium | 0.6% | 9.8 | Incorrect boundary conditions, integer overflow in the Libraries component in NS… | |
| CVE-2026-74990 | Medium | 0.5% | 9.8 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 a… | |
| CVE-2026-74987 | Medium | 0.5% | 9.8 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 a… | |
| CVE-2026-16353 | Medium | 0.5% | 9.8 | Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was … | |
| CVE-2026-8091 | Medium | 0.5% | 9.8 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulne… | |
| CVE-2026-16360 | Medium | 0.5% | 9.8 | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox… | |
| CVE-2026-74964 | Medium | 0.5% | 9.8 | Integer overflow in the Graphics component. This vulnerability was fixed in Fire… | |
| CVE-2026-75874 | Medium | 0.5% | 10.0 | Sandbox escape in the Remote Settings Client component. This vulnerability was f… | |
| CVE-2026-8094 | Medium | 0.4% | 9.8 | Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR… | |
| CVE-2026-16363 | Medium | 0.4% | 9.8 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability … | |
| CVE-2026-16369 | Medium | 0.4% | 9.8 | Integer overflow in the JavaScript: WebAssembly component. This vulnerability wa… | |
| CVE-2026-8975 | Medium | 0.4% | 8.8 | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox… | |
| CVE-2026-8968 | Medium | 0.4% | 7.5 | Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs componen… | |
| CVE-2026-74940 | Medium | 0.4% | 9.8 | Use-after-free in the Graphics: Text component. This vulnerability was fixed in … | |
| CVE-2026-16350 | Medium | 0.4% | 9.8 | Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerab… | |
| CVE-2026-16355 | Medium | 0.4% | 9.8 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2026-16357 | Medium | 0.4% | 9.8 | Incorrect boundary conditions in the Graphics component. This vulnerability was … | |
| CVE-2026-74936 | Medium | 0.4% | 9.8 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was … | |
| CVE-2026-74944 | Medium | 0.4% | 9.8 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-16351 | Medium | 0.4% | 9.8 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vuln… | |
| CVE-2026-16352 | Medium | 0.4% | 9.8 | Sandbox escape due to use-after-free in the Disability Access APIs component. Th… | |
| CVE-2026-16356 | Medium | 0.4% | 9.8 | Sandbox escape due to use-after-free in the Disability Access APIs component. Th… | |
| CVE-2026-16368 | Medium | 0.4% | 9.8 | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vul… | |
| CVE-2026-16377 | Medium | 0.4% | 9.8 | Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in F… | |
| CVE-2026-16383 | Medium | 0.4% | 9.8 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed… | |
| CVE-2026-8092 | Medium | 0.4% | 8.1 | Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Fir… | |
| CVE-2026-16382 | Medium | 0.4% | 9.8 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was … | |
| CVE-2026-84143 | Medium | 0.4% | 9.8 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thun… | |
| CVE-2026-16367 | Medium | 0.4% | 10.0 | Sandbox escape due to invalid pointer in the Disability Access APIs component. T… | |
| CVE-2026-16388 | Medium | 0.4% | 9.8 | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in… | |
| CVE-2026-8962 | Medium | 0.4% | 8.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-84145 | Medium | 0.4% | 7.5 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thun… | |
| CVE-2026-16376 | Medium | 0.4% | 7.5 | Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixe… | |
| CVE-2026-16392 | Medium | 0.4% | 9.1 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2026-74977 | Medium | 0.4% | 7.5 | Integer overflow in the Graphics component. This vulnerability was fixed in Fire… | |
| CVE-2026-74988 | Medium | 0.4% | 9.8 | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some… | |
| CVE-2026-74959 | Medium | 0.3% | 9.1 | Mitigation bypass in the Storage: Cache API component. This vulnerability was fi… | |
| CVE-2026-84141 | Medium | 0.3% | 9.8 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fix… | |
| CVE-2026-16354 | Medium | 0.3% | 7.5 | Information disclosure in the Graphics: ImageLib component. This vulnerability w… | |
| CVE-2026-84637 | Medium | 0.3% | 9.8 | Malicious calendar invitations could use file URI attachments to launch local or… | |
| CVE-2026-16402 | Medium | 0.3% | 9.8 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fix… |
Page 1 of 4
Next →