Thunderbird
Source repositories
CVEs (2,164)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22759 | Cri | 0.62 | 9.6 | 0.01 | Dec 22, 2022 | If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox… | ||
| CVE-2019-9813 | Hig | 0.61 | 8.8 | 0.07 | Apr 26, 2019 | Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1. | ||
| CVE-2026-92059 | Cri | 0.60 | 9.3 | 0.00 | Sep 15, 2026 | Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-8950 | Cri | 0.60 | 9.3 | 0.00 | May 19, 2026 | Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | ||
| CVE-2026-100763 | Cri | 0.59 | 9.1 | 0.00 | Sep 29, 2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||
| CVE-2026-92240 | Cri | 0.59 | 9.1 | 0.01 | Sep 15, 2026 | A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156,… | ||
| CVE-2026-92079 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-92075 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-92057 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-92051 | Cri | 0.59 | 9.1 | 0.01 | Sep 15, 2026 | Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||
| CVE-2026-92050 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||
| CVE-2026-92048 | Cri | 0.59 | 9.0 | 0.00 | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-92041 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-92038 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||
| CVE-2026-92034 | Cri | 0.59 | 9.1 | 0.00 | Sep 15, 2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||
| CVE-2026-84639 | Cri | 0.59 | 9.1 | 0.00 | Sep 1, 2026 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | ||
| CVE-2026-74961 | Cri | 0.59 | 9.1 | 0.00 | Aug 18, 2026 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74956 | Cri | 0.59 | 9.1 | 0.01 | Aug 18, 2026 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74938 | Cri | 0.59 | 9.1 | 0.00 | Aug 18, 2026 | Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-16406 | Cri | 0.59 | 9.1 | 0.00 | Jul 21, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
- risk 0.62cvss 9.6epss 0.01
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox…
- risk 0.61cvss 8.8epss 0.07
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
- risk 0.60cvss 9.3epss 0.00
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.60cvss 9.3epss 0.00
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- risk 0.59cvss 9.1epss 0.00
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- risk 0.59cvss 9.1epss 0.01
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156,…
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.59cvss 9.1epss 0.01
Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- risk 0.59cvss 9.1epss 0.00
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- risk 0.59cvss 9.0epss 0.00
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- risk 0.59cvss 9.1epss 0.00
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- risk 0.59cvss 9.1epss 0.00
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- risk 0.59cvss 9.1epss 0.00
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.01
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Page 20 of 109