VYPR

Thunderbird

by Mozilla Corporation

Source repositories

CVEs (2,087)

  • CVE-2016-9066HigJun 11, 2018
    risk 0.50cvss 7.5epss 0.12

    A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

  • CVE-2026-92044HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92042HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-84642HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was…

  • CVE-2026-84641HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84640HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84145HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-84144HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in…

  • CVE-2026-84132HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84130HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-74966HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74958HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74954HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-14899HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This…

  • CVE-2026-16409HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16405HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16400HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16399HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16398HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16391HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Page 41 of 105