VYPR

Thunderbird

by Mozilla Corporation

Source repositories

CVEs (2,164)

  • CVE-2022-22759CriDec 22, 2022
    risk 0.62cvss 9.6epss 0.01

    If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox…

  • CVE-2019-9813HigApr 26, 2019
    risk 0.61cvss 8.8epss 0.07

    Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

  • CVE-2026-92059CriSep 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-8950CriMay 19, 2026
    risk 0.60cvss 9.3epss 0.00

    Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

  • CVE-2026-100763CriSep 29, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

  • CVE-2026-92240CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.01

    A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156,…

  • CVE-2026-92079CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92075CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92057CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92051CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.01

    Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92050CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92048CriSep 15, 2026
    risk 0.59cvss 9.0epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92041CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92038CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92034CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-84639CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-74961CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74956CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74938CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-16406CriJul 21, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Page 20 of 109