Mozilla Thunderbird
196 known vulnerabilities in Mozilla Thunderbird, 55 critical, 9 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2024-9680 CVSS 9.8 critical · actively exploited Mozilla Firefox Use-After-Free Vulnerability
- CVE-2022-26486 CVSS 9.6 critical · actively exploited Mozilla Firefox Use-After-Free Vulnerability
- CVE-2022-26485 CVSS 8.8 high · actively exploited Mozilla Firefox Use-After-Free Vulnerability
- CVE-2020-6820 CVSS 8.1 high · actively exploited Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
- CVE-2020-6819 CVSS 8.1 high · actively exploited Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
- CVE-2019-17026 CVSS 8.8 high · actively exploited Mozilla Firefox And Thunderbird Type Confusion Vulnerability
- CVE-2019-11708 CVSS 10.0 critical · actively exploited Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
- CVE-2019-11707 CVSS 8.8 high · actively exploited Mozilla Firefox and Thunderbird Type Confusion Vulnerability
- CVE-2016-9079 CVSS 7.5 high · actively exploited Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
Latest vulnerabilities
- CVE-2026-103500 not yet scored An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This…
- CVE-2026-96869 CVSS 4.3 medium Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100832 CVSS 8.8 high Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Thunderbird…
- CVE-2026-100831 CVSS 8.8 high Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
- CVE-2026-100830 CVSS 8.1 high Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4…
- CVE-2026-100829 CVSS 9.6 critical Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4…
- CVE-2026-100828 CVSS 9.6 critical Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100826 CVSS 6.5 medium Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
- CVE-2026-100825 CVSS 8.8 high Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100824 CVSS 8.8 high Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and…
- CVE-2026-100822 CVSS 5.4 medium Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4…
- CVE-2026-100821 CVSS 4.7 medium Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100820 CVSS 8.8 high Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
- CVE-2026-100819 CVSS 9.6 critical Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird…
- CVE-2026-100818 CVSS 9.6 critical Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
- CVE-2026-100817 CVSS 5.4 medium Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- CVE-2026-100816 CVSS 8.1 high Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100815 CVSS 8.8 high Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
- CVE-2026-100814 CVSS 8.8 high Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
- CVE-2026-100813 CVSS 8.8 high Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- CVE-2026-100812 CVSS 6.5 medium Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and…
- CVE-2026-100811 CVSS 9.6 critical Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird…
- CVE-2026-100810 CVSS 9.8 critical Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- CVE-2026-100809 CVSS 8.1 high Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100808 CVSS 8.8 high Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100807 CVSS 8.8 high Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
- CVE-2026-100806 CVSS 4.3 medium Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
- CVE-2026-100805 CVSS 7.5 high Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- CVE-2026-100804 CVSS 9.6 critical Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- CVE-2026-100803 CVSS 8.1 high Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…