📦 Thunderbird

by Mozilla

🔍 What is Thunderbird?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-2806

CRITICAL CVSS 9.1 Feb 24, 2026

This vulnerability involves uninitialized memory in Firefox's Graphics: Text component, which could allow attackers to read sensitive data from memory or potentially execute arbitrary code. It affects...

CVE-2026-2796

CRITICAL CVSS 9.8 Feb 24, 2026

A JIT miscompilation vulnerability in Firefox's JavaScript: WebAssembly component could allow arbitrary code execution when processing malicious web content. This affects Firefox versions before 148, ...

CVE-2026-2800

CRITICAL CVSS 9.8 Feb 24, 2026

A spoofing vulnerability in the WebAuthn component of Firefox for Android allows attackers to potentially impersonate legitimate websites during authentication. This affects Firefox for Android versio...

CVE-2026-2786

CRITICAL CVSS 9.8 Feb 24, 2026

A use-after-free vulnerability in Firefox's JavaScript engine allows attackers to execute arbitrary code by tricking users into visiting malicious websites. This affects Firefox versions below 148 and...

CVE-2026-2788

CRITICAL CVSS 9.8 Feb 24, 2026

This vulnerability involves incorrect boundary conditions in the GMP (Gecko Media Plugins) audio/video component of Firefox, which could allow memory corruption. It affects Firefox versions below 148,...

CVE-2026-2790

CRITICAL CVSS 9.8 Feb 24, 2026

This CVE describes a same-origin policy bypass vulnerability in Firefox's JAR (Java Archive) networking component. It allows malicious websites to access data from other origins, potentially leading t...

CVE-2026-2792

CRITICAL CVSS 9.8 Feb 24, 2026

Memory safety vulnerabilities in Mozilla Firefox and Thunderbird could allow memory corruption attacks. With sufficient effort, attackers could exploit these bugs to execute arbitrary code on affected...

CVE-2026-2776

CRITICAL CVSS 10.0 Feb 24, 2026

This CVE describes a sandbox escape vulnerability in Firefox's Telemetry component due to incorrect boundary conditions. Attackers could potentially break out of browser security sandboxes to execute ...

CVE-2026-2778

CRITICAL CVSS 10.0 Feb 24, 2026

This CVE describes a sandbox escape vulnerability in Firefox's DOM Core & HTML component due to incorrect boundary conditions. It allows malicious web content to break out of browser security sandboxe...

CVE-2026-2780

CRITICAL CVSS 9.8 Feb 24, 2026

This CVE describes a privilege escalation vulnerability in Firefox's Netmonitor component. Attackers could exploit this to gain elevated privileges within the browser. It affects Firefox versions belo...

CVE-2026-2782

CRITICAL CVSS 9.8 Feb 24, 2026

This CVE describes a privilege escalation vulnerability in Firefox's Netmonitor component that allows attackers to gain elevated privileges on affected systems. It affects Firefox versions below 148 a...

CVE-2026-2784

CRITICAL CVSS 9.8 Feb 24, 2026

This CVE describes a DOM security component mitigation bypass vulnerability in Firefox. Attackers could potentially bypass security controls to execute malicious code or access restricted content. Aff...

CVE-2026-2768

CRITICAL CVSS 10.0 Feb 24, 2026

This CVE describes a sandbox escape vulnerability in Firefox's IndexedDB storage component. Attackers could potentially break out of browser security restrictions to execute arbitrary code. Affects Fi...

CVE-2026-2770

CRITICAL CVSS 9.8 Feb 24, 2026

This CVE describes a use-after-free vulnerability in Firefox's DOM Bindings (WebIDL) component that could allow an attacker to execute arbitrary code. It affects Firefox versions below 148, Firefox ES...

CVE-2026-2772

CRITICAL CVSS 9.8 Feb 24, 2026

A use-after-free vulnerability in Firefox's audio/video playback component allows attackers to execute arbitrary code or cause crashes. This affects Firefox versions below 148, Firefox ESR below 115.3...

CVE-2026-2774

CRITICAL CVSS 9.8 Feb 24, 2026

An integer overflow vulnerability in Firefox's Audio/Video component could allow attackers to execute arbitrary code or cause denial of service. This affects Firefox versions below 148, Firefox ESR be...

CVE-2026-2758

CRITICAL CVSS 9.8 Feb 24, 2026

A use-after-free vulnerability in Firefox's JavaScript garbage collector component allows attackers to execute arbitrary code by manipulating memory after it has been freed. This affects Firefox versi...

CVE-2026-2760

CRITICAL CVSS 10.0 Feb 24, 2026

This CVE describes a sandbox escape vulnerability in Firefox's WebRender graphics component due to incorrect boundary conditions. It allows attackers to break out of browser security sandboxes and pot...

CVE-2026-2762

CRITICAL CVSS 9.8 Feb 24, 2026

An integer overflow vulnerability in Firefox's JavaScript Standard Library component could allow attackers to execute arbitrary code or cause denial of service. This affects Firefox versions below 148...

CVE-2026-2764

CRITICAL CVSS 9.8 Feb 24, 2026

This CVE describes a use-after-free vulnerability in Firefox's JavaScript JIT compiler that could allow arbitrary code execution. It affects Firefox versions below 148 and Firefox ESR versions below 1...

CVE-2026-2798

HIGH CVSS 8.8 Feb 24, 2026

This CVE describes a use-after-free vulnerability in Firefox's DOM Core & HTML components that could allow attackers to execute arbitrary code or cause crashes. It affects Firefox versions before 148....

CVE-2026-2447

HIGH CVSS 8.8 Feb 16, 2026

A heap buffer overflow vulnerability in libvpx video codec library allows attackers to execute arbitrary code or cause denial of service. This affects Firefox browsers below specific versions across m...

CVE-2026-0889

HIGH CVSS 7.5 Jan 13, 2026

A denial-of-service vulnerability in Firefox and Thunderbird's DOM Service Workers component allows attackers to crash the browser or email client. This affects users running Firefox versions below 14...

CVE-2026-0891

HIGH CVSS 8.1 Jan 13, 2026

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to execute arbi...

CVE-2026-0877

HIGH CVSS 8.1 Jan 13, 2026

This CVE describes a mitigation bypass vulnerability in the DOM Security component of Mozilla products. It allows attackers to circumvent security protections, potentially leading to arbitrary code ex...

CVE-2026-0878

HIGH CVSS 8.0 Jan 13, 2026

This CVE describes a sandbox escape vulnerability in the Graphics: CanvasWebGL component due to incorrect boundary conditions. It allows attackers to break out of browser security sandboxes and execut...

CVE-2026-0880

HIGH CVSS 8.8 Jan 13, 2026

This CVE describes an integer overflow vulnerability in the Graphics component of Mozilla products that allows sandbox escape. Attackers could exploit this to execute arbitrary code outside the browse...

CVE-2026-0882

HIGH CVSS 8.8 Jan 13, 2026

A use-after-free vulnerability in Firefox and Thunderbird's IPC component allows attackers to execute arbitrary code or cause denial of service. This affects Firefox versions below 147 and specific ES...

CVE-2025-14325

HIGH CVSS 7.3 Dec 9, 2025

A JIT (Just-In-Time) compilation vulnerability in Mozilla's JavaScript engine allows memory corruption through miscompiled code. This affects Firefox, Firefox ESR, and Thunderbird users running outdat...

CVE-2025-14327

HIGH CVSS 7.5 Dec 9, 2025

This vulnerability allows attackers to spoof download notifications in Firefox and Thunderbird, potentially tricking users into executing malicious files. It affects all users running vulnerable versi...

CVE-2025-14328

HIGH CVSS 8.8 Dec 9, 2025

This CVE describes a privilege escalation vulnerability in the Netmonitor component of Mozilla products. It allows attackers to gain elevated privileges on affected systems. The vulnerability affects ...

CVE-2025-14329

HIGH CVSS 8.8 Dec 9, 2025

This CVE describes a privilege escalation vulnerability in the Netmonitor component of Mozilla products. Attackers could exploit this to gain elevated privileges on affected systems. It affects Firefo...

CVE-2025-14332

HIGH CVSS 7.3 Dec 9, 2025

Memory safety bugs in Firefox and Thunderbird could allow attackers to corrupt memory and potentially execute arbitrary code. This affects all users running Firefox versions before 146 or Thunderbird ...

CVE-2025-14333

HIGH CVSS 8.1 Dec 9, 2025

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to exec...

CVE-2025-14322

HIGH CVSS 8.0 Dec 9, 2025

This CVE describes a sandbox escape vulnerability in Firefox and Thunderbird's Graphics: CanvasWebGL component due to incorrect boundary conditions. It allows attackers to break out of browser sandbox...

CVE-2025-14323

HIGH CVSS 8.8 Dec 9, 2025

This CVE describes a privilege escalation vulnerability in the DOM Notifications component of Mozilla products. It allows attackers to elevate privileges within the browser context, potentially execut...

CVE-2025-11713

HIGH CVSS 8.1 Oct 14, 2025

This vulnerability in Firefox and Thunderbird's 'Copy as cURL' feature allows insufficient escaping on Windows systems, potentially tricking users into executing malicious code. Attackers could craft ...

CVE-2025-11715

HIGH CVSS 8.8 Oct 14, 2025

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to execute arbi...

CVE-2025-10537

HIGH CVSS 8.8 Sep 16, 2025

This CVE describes memory safety vulnerabilities in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these bugs to execute arbi...

CVE-2025-10533

HIGH CVSS 8.8 Sep 16, 2025

An integer overflow vulnerability in the SVG component of Mozilla products allows attackers to execute arbitrary code or cause denial of service. This affects Firefox, Firefox ESR, and Thunderbird use...

CVE-2025-10527

HIGH CVSS 7.1 Sep 16, 2025

This CVE describes a use-after-free vulnerability in the Canvas2D graphics component of Mozilla products, allowing sandbox escape. Attackers could exploit this to execute arbitrary code with elevated ...

CVE-2025-9182

HIGH CVSS 7.5 Aug 19, 2025

This vulnerability allows attackers to cause denial-of-service through memory exhaustion in Firefox and Thunderbird's WebRender graphics component. It affects all users running vulnerable versions of ...

CVE-2025-9184

HIGH CVSS 8.1 Aug 19, 2025

This CVE describes memory safety vulnerabilities in Firefox and Thunderbird that could allow memory corruption. With sufficient effort, attackers could potentially exploit these bugs to execute arbitr...

CVE-2025-8039

HIGH CVSS 8.1 Jul 22, 2025

This vulnerability allows search terms to persist in the URL bar after navigating away from search pages, potentially exposing sensitive search queries. It affects Firefox, Firefox ESR, Thunderbird, a...

CVE-2025-8034

HIGH CVSS 8.8 Jul 22, 2025

This CVE describes memory safety bugs in multiple Mozilla products that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to execute ar...

CVE-2025-8036

HIGH CVSS 8.1 Jul 22, 2025

This vulnerability in Thunderbird and Firefox allows attackers to bypass Cross-Origin Resource Sharing (CORS) protections using DNS rebinding attacks. By exploiting cached CORS preflight responses acr...

CVE-2025-6435

HIGH CVSS 8.1 Jun 24, 2025

This vulnerability in Firefox and Thunderbird allows saved files from the Network tab in Devtools to lack the .download extension, potentially causing users to inadvertently execute malicious files. A...

CVE-2025-5272

HIGH CVSS 7.3 May 27, 2025

Memory safety vulnerabilities in Firefox and Thunderbird could allow attackers to corrupt memory and potentially execute arbitrary code. This affects all users running Firefox versions before 139 or T...

CVE-2025-5268

HIGH CVSS 8.1 May 27, 2025

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to execute arbi...

CVE-2025-5262

HIGH CVSS 7.5 May 27, 2025

A double-free vulnerability in Thunderbird's WebRTC encoder initialization could cause memory corruption and potentially exploitable crashes. This affects Thunderbird email clients on all platforms. A...

CVE-2025-3909

HIGH CVSS 8.1 May 14, 2025

This vulnerability in Thunderbird allows attackers to execute JavaScript in the file:/// context by crafting a malicious email attachment. When Thunderbird incorrectly renders a nested message/rfc822 ...

CVE-2025-4085

HIGH CVSS 7.1 Apr 29, 2025

This vulnerability allows an attacker with control over a content process to abuse the privileged UITour actor, potentially leading to information disclosure or privilege escalation. It affects users ...

CVE-2025-4091

HIGH CVSS 8.1 Apr 29, 2025

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to exec...

CVE-2025-4093

HIGH CVSS 8.1 Apr 29, 2025

A memory safety vulnerability in Firefox ESR and Thunderbird could allow attackers to execute arbitrary code on affected systems. This affects Firefox ESR versions before 128.10 and Thunderbird versio...

CVE-2025-2817

HIGH CVSS 8.8 Apr 29, 2025

This vulnerability allows a medium-integrity user process to interfere with Thunderbird's SYSTEM-level updater by manipulating file-locking behavior. An attacker can inject code to bypass access contr...

CVE-2025-3029

HIGH CVSS 7.3 Apr 1, 2025

This vulnerability allows attackers to craft URLs with specific Unicode characters that hide the true origin of web pages, enabling spoofing attacks. It affects Firefox, Firefox ESR, and Thunderbird u...

CVE-2025-3032

HIGH CVSS 7.4 Apr 1, 2025

This vulnerability allows file descriptors from the fork server to leak into web content processes, potentially enabling privilege escalation attacks. It affects Firefox versions before 137 and Thunde...

CVE-2025-3034

HIGH CVSS 8.1 Apr 1, 2025

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to execute arbi...

CVE-2025-26696

HIGH CVSS 7.0 Mar 10, 2025

This vulnerability in Thunderbird email client incorrectly displays signed OpenPGP messages as encrypted messages when crafted MIME emails claim to contain encryption. This affects Thunderbird users o...

CVE-2025-1943

HIGH CVSS 8.2 Mar 4, 2025

CVE-2025-1943 is a heap-based buffer overflow vulnerability in Firefox and Thunderbird that could allow memory corruption. Attackers could potentially exploit this to execute arbitrary code on affecte...

CVE-2026-2802

MEDIUM CVSS 4.2 Feb 24, 2026

A race condition vulnerability in Firefox's JavaScript garbage collector (GC) component could allow attackers to execute arbitrary code or cause denial of service. This affects Firefox versions before...

CVE-2026-2804

MEDIUM CVSS 5.4 Feb 24, 2026

A use-after-free vulnerability in Firefox's WebAssembly JavaScript component allows attackers to execute arbitrary code by manipulating freed memory. This affects all Firefox users running versions be...

CVE-2026-0818

MEDIUM CVSS 4.3 Jan 28, 2026

This vulnerability in Thunderbird allows attackers to exfiltrate decrypted OpenPGP email contents through CSS injection when users load remote content. It affects Thunderbird users who decrypt inline ...

CVE-2026-0885

MEDIUM CVSS 6.5 Jan 13, 2026

This CVE describes a use-after-free vulnerability in the JavaScript garbage collection component of Mozilla products. Attackers could exploit this to execute arbitrary code or cause crashes by manipul...

CVE-2026-0886

MEDIUM CVSS 5.3 Jan 13, 2026

A memory corruption vulnerability in Firefox and Thunderbird's graphics component due to incorrect boundary conditions. This could allow attackers to execute arbitrary code or cause denial of service....

CVE-2026-0887

MEDIUM CVSS 4.3 Jan 13, 2026

This CVE describes a clickjacking vulnerability in the PDF Viewer component of Mozilla products that could allow information disclosure. Attackers could trick users into clicking hidden UI elements, p...

CVE-2026-0888

MEDIUM CVSS 5.3 Jan 13, 2026

This CVE describes an information disclosure vulnerability in the XML component of Firefox and Thunderbird. It allows attackers to potentially access sensitive data from affected browsers. Users runni...

CVE-2026-0890

MEDIUM CVSS 5.4 Jan 13, 2026

This CVE describes a spoofing vulnerability in Firefox and Thunderbird's DOM copy-paste and drag-drop components. Attackers can manipulate clipboard or drag-drop operations to trick users into interac...

CVE-2026-0883

MEDIUM CVSS 5.3 Jan 13, 2026

This CVE describes an information disclosure vulnerability in the Networking component of Mozilla products. It allows attackers to potentially access sensitive information from affected browsers and e...

CVE-2025-14331

MEDIUM CVSS 6.5 Dec 9, 2025

This CVE describes a same-origin policy bypass vulnerability in Firefox and Thunderbird's request handling component. It allows malicious websites to access data from other origins they shouldn't have...

CVE-2025-11712

MEDIUM CVSS 6.1 Oct 14, 2025

This vulnerability allows malicious web pages to bypass browser security controls using OBJECT tags when servers don't provide proper content-type headers. Attackers could potentially execute cross-si...

CVE-2025-10532

MEDIUM CVSS 6.5 Sep 16, 2025

This vulnerability involves incorrect boundary conditions in Firefox and Thunderbird's JavaScript garbage collector (GC) component, which could allow an attacker to execute arbitrary code or cause a d...

CVE-2025-10530

MEDIUM CVSS 6.5 Sep 16, 2025

A spoofing vulnerability in Firefox for Android's WebAuthn component allows attackers to bypass authentication by presenting fake credentials. This affects Firefox for Android versions below 143 and T...

CVE-2025-10531

MEDIUM CVSS 5.4 Sep 16, 2025

This CVE describes a mitigation bypass vulnerability in the Web Compatibility: Tooling component of Firefox and Thunderbird. Attackers could potentially bypass security mitigations to execute arbitrar...

CVE-2025-10529

MEDIUM CVSS 6.5 Sep 16, 2025

This CVE describes a same-origin policy bypass vulnerability in the Layout component of Mozilla products. It allows malicious websites to access data from other origins they shouldn't have access to, ...

CVE-2025-9181

MEDIUM CVSS 6.5 Aug 19, 2025

This vulnerability involves uninitialized memory in the JavaScript Engine component of Mozilla products, which could allow an attacker to execute arbitrary code or cause a crash. It affects Firefox, F...

CVE-2025-4087

MEDIUM CVSS 4.8 Apr 29, 2025

This vulnerability in Thunderbird and Firefox allows attackers to trigger undefined behavior through XPath parsing, potentially leading to out-of-bounds memory reads and memory corruption. It affects ...

CVE-2025-4089

MEDIUM CVSS 5.1 Apr 29, 2025

This vulnerability in Firefox and Thunderbird's 'copy as cURL' feature allows attackers to craft malicious commands with insufficient escaping of special characters. If a user copies and executes such...

CVE-2025-3523

MEDIUM CVSS 6.4 Apr 15, 2025

This vulnerability in Thunderbird email client causes misleading hover text when emails contain multiple attachments with external links. Only the last link appears when hovering over any attachment, ...

CVE-2025-3028

MEDIUM CVSS 6.5 Apr 1, 2025

This vulnerability allows JavaScript code to trigger a use-after-free condition during XSLT document transformations in Mozilla browsers and email clients. Attackers could exploit this to execute arbi...

CVE-2025-3031

MEDIUM CVSS 6.5 Apr 1, 2025

This vulnerability allows an attacker to read 32 bits of sensitive data from the stack in JIT-compiled JavaScript functions. It affects Firefox web browser versions before 137 and Thunderbird email cl...

CVE-2025-1934

MEDIUM CVSS 6.5 Mar 4, 2025

This vulnerability allows an attacker to interrupt RegExp bailout processing and execute additional JavaScript, potentially triggering unexpected garbage collection in the JavaScript engine. This affe...

CVE-2025-1938

MEDIUM CVSS 6.5 Mar 4, 2025

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to execute arbi...

CVE-2025-1013

MEDIUM CVSS 6.5 Feb 4, 2025

A race condition vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird could cause private browsing tabs to open in normal browsing windows, potentially leaking private browsing data. This af...

CVE-2025-1018

MEDIUM CVSS 5.3 Feb 4, 2025

This vulnerability allows attackers to hide the fullscreen notification in Firefox and Thunderbird by rapidly requesting fullscreen mode, enabling potential UI spoofing attacks. It affects users runni...

CVE-2025-1015

MEDIUM CVSS 5.4 Feb 4, 2025

This vulnerability allows attackers to embed malicious links in Thunderbird address book fields. When another user imports the infected address book and clicks the link, JavaScript executes within Thu...

CVE-2025-0510

MEDIUM CVSS 6.5 Feb 4, 2025

Thunderbird email client displays incorrect sender addresses when emails use invalid group name syntax in the From field. This allows attackers to spoof sender identities, potentially tricking users i...

CVE-2025-0237

MEDIUM CVSS 5.4 Jan 7, 2025

This vulnerability in Mozilla's WebChannel API allows privilege escalation by accepting arbitrary principal information from untrusted sources. Attackers could exploit this to gain elevated privileges...

CVE-2025-0239

MEDIUM CVSS 4.0 Jan 7, 2025

This vulnerability allows attackers to bypass certificate validation when Firefox or Thunderbird redirects from a secure server to an insecure one using Alt-Svc. This could enable man-in-the-middle at...

CVE-2025-0242

MEDIUM CVSS 6.5 Jan 7, 2025

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potentially exploit these vulnerabilities to exec...