Skip to main content

Vendor/product archive

mozilla / thunderbird CVEs

Beta · best-effort

1,775 CVEs tagged to mozilla / thunderbird607 Critical, 527 High, 615 Medium, 26 Low, 0 Unrated.

CVE-2026-0884

Published Jan 13, 2026

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-0883

Published Jan 13, 2026

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-0882

Published Jan 13, 2026

Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 8.8 · High
evidence mentions
32
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-0880

Published Jan 13, 2026

Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderb…

CVSS 8.8 · High
evidence mentions
32
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-0879

Published Jan 13, 2026

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147,…

CVSS 9.8 · Critical
evidence mentions
32
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-0878

Published Jan 13, 2026

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Th…

CVSS 8.0 · High
evidence mentions
31
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-0877

Published Jan 13, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 8.1 · High
evidence mentions
32
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-14332

Published Dec 9, 2025

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14331

Published Dec 9, 2025

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14329

Published Dec 9, 2025

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14328

Published Dec 9, 2025

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14325

Published Dec 9, 2025

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14324

Published Dec 9, 2025

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-14323

Published Dec 9, 2025

Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14322

Published Dec 9, 2025

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thu…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11721

Published Oct 14, 2025

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-11715

Published Oct 14, 2025

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume tha…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 1,775 CVEsPage 9 of 71