mozilla / thunderbird
172 known vulnerabilities in mozilla thunderbird.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-8969 | Medium | 0.3% | 8.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-16409 | Medium | 0.3% | 7.5 | Invalid pointer in the Security: PSM component. This vulnerability was fixed in … | |
| CVE-2026-74956 | Medium | 0.3% | 9.1 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerabil… | |
| CVE-2026-16407 | Medium | 0.3% | 9.8 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was … | |
| CVE-2026-16365 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed… | |
| CVE-2026-16379 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Content Processes component. This vulnerability… | |
| CVE-2026-14899 | Medium | 0.3% | 7.5 | The code to parse MIME headers for display when forwarding a message (if the set… | |
| CVE-2026-16366 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-84641 | Medium | 0.3% | 7.5 | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by… | |
| CVE-2026-74958 | Medium | 0.3% | 7.5 | Information disclosure in the WebRTC component. This vulnerability was fixed in … | |
| CVE-2026-16359 | Medium | 0.3% | 9.1 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerabil… | |
| CVE-2026-84640 | Medium | 0.3% | 7.5 | A maliciously constructed mail header could lead to a one byte read past the end… | |
| CVE-2026-74954 | Medium | 0.3% | 7.5 | Information disclosure due to side-channel in the Storage: Cache API component. … | |
| CVE-2026-74966 | Medium | 0.3% | 7.5 | Information disclosure in the Form Autofill component. This vulnerability was fi… | |
| CVE-2026-84130 | Medium | 0.3% | 7.5 | Information disclosure in the Graphics: WebGPU component. This vulnerability was… | |
| CVE-2026-84132 | Medium | 0.3% | 7.5 | Information disclosure in the Networking: HTTP component. This vulnerability was… | |
| CVE-2026-84642 | Medium | 0.3% | 7.5 | The values of the mail.allowed_attachment_hostnames advanced config setting were… | |
| CVE-2026-74961 | Medium | 0.3% | 9.1 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox… | |
| CVE-2026-16400 | Medium | 0.2% | 7.5 | Information disclosure in the DOM: Security component. This vulnerability was fi… | |
| CVE-2026-74947 | Medium | 0.2% | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vuln… | |
| CVE-2026-16396 | Medium | 0.2% | 8.8 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 1… | |
| CVE-2026-84144 | Medium | 0.2% | 7.5 | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some… | |
| CVE-2026-84123 | Medium | 0.2% | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. Th… | |
| CVE-2026-84128 | Medium | 0.2% | 8.8 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fix… | |
| CVE-2026-74978 | Medium | 0.2% | 8.1 | Clickjacking issue in the Widget component. This vulnerability was fixed in Fire… | |
| CVE-2026-74952 | Medium | 0.2% | 8.8 | Privilege escalation in the Application Update component. This vulnerability was… | |
| CVE-2026-74950 | Medium | 0.2% | 8.8 | Privilege escalation in the Downloads API component. This vulnerability was fixe… | |
| CVE-2026-74955 | Medium | 0.2% | 8.8 | Privilege escalation in the Request Handling component. This vulnerability was f… | |
| CVE-2026-16358 | Medium | 0.2% | 9.8 | Site isolation issue in the Graphics: WebRender component. This vulnerability wa… | |
| CVE-2026-16349 | Medium | 0.2% | 9.8 | Same-origin policy bypass in the DOM: Navigation component. This vulnerability w… | |
| CVE-2026-16401 | Medium | 0.2% | 8.8 | Privilege escalation in the Data Loss Prevention component. This vulnerability w… | |
| CVE-2026-16375 | Medium | 0.2% | 9.8 | Site isolation issue in the Networking: HTTP component. This vulnerability was f… | |
| CVE-2026-16387 | Medium | 0.2% | 9.8 | Site isolation issue in the Networking component. This vulnerability was fixed i… | |
| CVE-2026-84129 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-84133 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Push Subscriptions component. This vulnerabilit… | |
| CVE-2026-84140 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-16381 | Medium | 0.2% | 9.1 | Same-origin policy bypass in the Networking: DNS component. This vulnerability w… | |
| CVE-2026-74960 | Medium | 0.2% | 8.1 | Site isolation issue in the WebExtensions component. This vulnerability was fixe… | |
| CVE-2026-74962 | Medium | 0.2% | 8.1 | Site isolation issue in the Networking: Cookies component. This vulnerability wa… | |
| CVE-2026-74934 | Medium | 0.2% | 7.5 | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability … | |
| CVE-2026-16398 | Medium | 0.1% | 7.5 | Site isolation issue in the Graphics component. This vulnerability was fixed in … | |
| CVE-2026-16399 | Medium | 0.1% | 7.5 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-74981 | Medium | 0.1% | 8.1 | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerabilit… | |
| CVE-2020-15664 | Low | 1.4% | 6.5 | By holding a reference to the eval() function from an about:blank window, a mali… | |
| CVE-2023-29535 | Low | 0.7% | 6.5 | Following a Garbage Collector compaction, weak maps may have been accessed befor… | |
| CVE-2023-29548 | Low | 0.7% | 6.5 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optim… | |
| CVE-2023-29533 | Low | 0.6% | 4.3 | A website could have obscured the fullscreen notification by using a combination… | |
| CVE-2026-74945 | Low | 0.4% | 6.5 | Information disclosure in the Graphics: Text component. This vulnerability was f… | |
| CVE-2026-8961 | Low | 0.3% | 6.5 | Spoofing issue in the Form Autofill component. This vulnerability was fixed in F… | |
| CVE-2026-74976 | Low | 0.3% | 6.5 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… |