Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,840 CVEs tagged to mozilla / thunderbird642 Critical, 555 High, 617 Medium, 26 Low, 0 Unrated.

CVE-2025-14331

Published Dec 9, 2025

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2025-14329

Published Dec 9, 2025

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-14328

Published Dec 9, 2025

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-14327

Published Dec 9, 2025

Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-14325

Published Dec 9, 2025

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 7.3 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-14324

Published Dec 9, 2025

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2025-14323

Published Dec 9, 2025

Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.…

CVSS 8.8 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2025-14322

Published Dec 9, 2025

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thu…

CVSS 8.0 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2025-14321

Published Dec 9, 2025

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-11721

Published Oct 14, 2025

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited t…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-11715

Published Oct 14, 2025

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume tha…

CVSS 8.8 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-11713

Published Oct 14, 2025

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when runnin…

CVSS 8.1 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-11712

Published Oct 14, 2025

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This…

CVSS 6.1 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-11711

Published Oct 14, 2025

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefo…

CVSS 6.5 · Medium
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2025-11710

Published Oct 14, 2025

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerabili…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2025-11709

Published Oct 14, 2025

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2025-11708

Published Oct 14, 2025

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10537

Published Sep 16, 2025

Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume tha…

CVSS 8.8 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-10536

Published Sep 16, 2025

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVSS 6.2 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,840 CVEsPage 12 of 74