Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,775 CVEs tagged to mozilla / thunderbird607 Critical, 527 High, 615 Medium, 26 Low, 0 Unrated.

CVE-2026-2771

Published Feb 24, 2026

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2770

Published Feb 24, 2026

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2769

Published Feb 24, 2026

Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 8.8 · High
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2768

Published Feb 24, 2026

Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 10.0 · Critical
evidence mentions
33
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2767

Published Feb 24, 2026

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
33
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2766

Published Feb 24, 2026

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
33
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2765

Published Feb 24, 2026

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
33
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2764

Published Feb 24, 2026

JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, an…

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2763

Published Feb 24, 2026

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2762

Published Feb 24, 2026

Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
33
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2761

Published Feb 24, 2026

Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 10.0 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2760

Published Feb 24, 2026

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thund…

CVSS 10.0 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2759

Published Feb 24, 2026

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunder…

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2758

Published Feb 24, 2026

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2757

Published Feb 24, 2026

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunde…

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2447

Published Feb 16, 2026

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

CVSS 8.8 · High
evidence mentions
49
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2026-0818

Published Jan 28, 2026

When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS,…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-0892

Published Jan 13, 2026

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-0891

Published Jan 13, 2026

Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume tha…

CVSS 8.1 · High
evidence mentions
32
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-0890

Published Jan 13, 2026

Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-0887

Published Jan 13, 2026

Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-0886

Published Jan 13, 2026

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-0885

Published Jan 13, 2026

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort
Showing 176-200 of 1,775 CVEsPage 8 of 71