Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,775 CVEs tagged to mozilla / thunderbird607 Critical, 527 High, 615 Medium, 26 Low, 0 Unrated.

CVE-2025-11713

Published Oct 14, 2025

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when runnin…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11712

Published Oct 14, 2025

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11711

Published Oct 14, 2025

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11710

Published Oct 14, 2025

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerabili…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-11709

Published Oct 14, 2025

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-11708

Published Oct 14, 2025

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-10537

Published Sep 16, 2025

Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume tha…

CVSS 8.8 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10536

Published Sep 16, 2025

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVSS 6.2 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10533

Published Sep 16, 2025

Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVSS 8.8 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10532

Published Sep 16, 2025

Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVSS 6.5 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10531

Published Sep 16, 2025

Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-10530

Published Sep 16, 2025

Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-10529

Published Sep 16, 2025

Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVSS 6.5 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10528

Published Sep 16, 2025

Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and…

CVSS 7.3 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10527

Published Sep 16, 2025

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVSS 7.1 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-9187

Published Aug 19, 2025

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9185

Published Aug 19, 2025

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of th…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9184

Published Aug 19, 2025

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume tha…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9182

Published Aug 19, 2025

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9181

Published Aug 19, 2025

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9180

Published Aug 19, 2025

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9179

Published Aug 19, 2025

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different pri…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8044

Published Jul 22, 2025

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 226-250 of 1,775 CVEsPage 10 of 71